Rustls · Rustls · CVE-2024-11738
**Name of the Vulnerable Software and Affected Versions**
Rustls version 0.23.13
**Description**
A flaw was found in Rustls and related APIs, allowing denial of service (panic) via a fragmented TLS ClientHello message.
**Recommendations**
For Rustls version 0.23.13, consider disabling the handling of fragmented TLS ClientHello messages as a temporary workaround until a patch is available.