{"id":"RUSTSEC-2026-0287","title":"cosmian_kyber is unmaintained","summary":"cosmian_kyber is unmaintained","severity":"none","vendor":"cosmian_kyber","product":"cosmian_kyber","ecosystem":"rust","affected":["cosmian_kyber >= 0.0.0-0"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T09:15:05.147975858Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0287","references":[{"url":"https://crates.io/crates/cosmian_kyber"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0287.html"},{"url":"https://github.com/Cosmian/kyber/pull/6"}],"tags":["osv","rust"],"ingestedAt":"2026-09-18T16:21:29.496Z","slug":"RUSTSEC-2026-0287","body":"## Overview\n\n`cosmian_kyber` is a fork of `Argyle-Software/kyber` that has seen no maintainer\nactivity. It inherits the fork parent's broken AVX2 constant-time code, and the\nopen fix pull request (Cosmian/kyber#6) has gone unanswered.\n\nRecommended alternatives:\n\n- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)\n- [graviola](https://crates.io/crates/graviola)\n\n## Affected packages\n\n- `cosmian_kyber >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}