{"id":"RUSTSEC-2026-0206","title":"`rustybuzz` is unmaintained","summary":"`rustybuzz` is unmaintained","severity":"none","vendor":"rustybuzz","product":"rustybuzz","ecosystem":"rust","affected":["rustybuzz >= 0.0.0-0"],"published":"2026-07-11","updated":"2026-07-12","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0206","references":[{"url":"https://crates.io/crates/rustybuzz"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0206.html"},{"url":"https://github.com/harfbuzz/rustybuzz/issues/166"}],"tags":["osv","rust"],"ingestedAt":"2026-07-12T18:57:28.205Z","slug":"RUSTSEC-2026-0206","body":"## Overview\n\nThe current maintainer of `rustybuzz` has stated that the crate is unmaintained and will not receive further fixes or updates (see the referenced issue).\n\n## Alternative(s)\n\n- [`harfrust`](https://github.com/harfbuzz/harfrust), an actively maintained and updated alternative which is part of the Harfbuzz project.\n\n## Affected packages\n\n- `rustybuzz >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}