{"id":"RUSTSEC-2026-0289","summary":"pqc_kyber is unmaintained","details":"The crate has had no releases since 0.7.1 (2023-08-23), and the upstream\nrepository shows no maintainer activity. Open pull requests, including a fix for\na chosen-ciphertext key-recovery flaw in the AVX2 backend\n(Argyle-Software/kyber#121), have gone unanswered.\n\nRecommended alternatives:\n\n- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)\n- [graviola](https://crates.io/crates/graviola)","modified":"2026-09-18T09:15:05.128570230Z","published":"2026-09-17T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/pqc_kyber"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0289.html"},{"type":"WEB","url":"https://github.com/Argyle-Software/kyber/pull/121"}],"affected":[{"package":{"name":"pqc_kyber","ecosystem":"crates.io","purl":"pkg:cargo/pqc_kyber"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"arch":[],"os":[],"functions":[]},"affected_functions":null},"database_specific":{"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0289.json","categories":[],"cvss":null,"informational":"unmaintained"}}],"schema_version":"1.9.0"}