rustsec-2026-0289
osv_rustsec
Description
The crate has had no releases since 0.7.1 (2023-08-23), and the upstream repository shows no maintainer activity. Open pull requests, including a fix for a chosen-ciphertext key-recovery flaw in the AVX2 backend (Argyle-Software/kyber#121), have gone unanswered. Recommended alternatives: - [aws-lc-rs](https://crates.io/crates/aws-lc-rs) - [graviola](https://crates.io/crates/graviola)
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
Linked Vulnerabilities
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"categories": [],
"cvss": null,
"informational": "unmaintained",
"source": "https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0289.json"
},
"ecosystem_specific": {
"affected_functions": null,
"affects": {
"arch": [],
"functions": [],
"os": []
}
},
"package": {
"ecosystem": "crates.io",
"name": "pqc_kyber",
"purl": "pkg:cargo/pqc_kyber"
},
"ranges": [
{
"events": [
{
"introduced": "0.0.0-0"
}
],
"type": "SEMVER"
}
]
}
],
"database_specific": {
"license": "CC0-1.0"
},
"details": "The crate has had no releases since 0.7.1 (2023-08-23), and the upstream\nrepository shows no maintainer activity. Open pull requests, including a fix for\na chosen-ciphertext key-recovery flaw in the AVX2 backend\n(Argyle-Software/kyber#121), have gone unanswered.\n\nRecommended alternatives:\n\n- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)\n- [graviola](https://crates.io/crates/graviola)",
"id": "RUSTSEC-2026-0289",
"modified": "2026-09-18T09:15:05.128570230Z",
"published": "2026-09-17T12:00:00Z",
"references": [
{
"type": "PACKAGE",
"url": "https://crates.io/crates/pqc_kyber"
},
{
"type": "ADVISORY",
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0289.html"
},
{
"type": "WEB",
"url": "https://github.com/Argyle-Software/kyber/pull/121"
}
],
"schema_version": "1.9.0",
"summary": "pqc_kyber is unmaintained"
}