{"affected":[{"database_specific":{"categories":[],"cvss":null,"informational":"unmaintained","source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0289.json"},"ecosystem_specific":{"affected_functions":null,"affects":{"arch":[],"functions":[],"os":[]}},"package":{"ecosystem":"crates.io","name":"pqc_kyber","purl":"pkg:cargo/pqc_kyber"},"ranges":[{"events":[{"introduced":"0.0.0-0"}],"type":"SEMVER"}]}],"database_specific":{"license":"CC0-1.0"},"details":"The crate has had no releases since 0.7.1 (2023-08-23), and the upstream\nrepository shows no maintainer activity. Open pull requests, including a fix for\na chosen-ciphertext key-recovery flaw in the AVX2 backend\n(Argyle-Software/kyber#121), have gone unanswered.\n\nRecommended alternatives:\n\n- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)\n- [graviola](https://crates.io/crates/graviola)","id":"RUSTSEC-2026-0289","modified":"2026-09-18T09:15:05.128570230Z","published":"2026-09-17T12:00:00Z","references":[{"type":"PACKAGE","url":"https://crates.io/crates/pqc_kyber"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0289.html"},{"type":"WEB","url":"https://github.com/Argyle-Software/kyber/pull/121"}],"schema_version":"1.9.0","summary":"pqc_kyber is unmaintained"}