{"id":"RUSTSEC-2026-0289","title":"pqc_kyber is unmaintained","summary":"pqc_kyber is unmaintained","severity":"none","vendor":"pqc_kyber","product":"pqc_kyber","ecosystem":"rust","affected":["pqc_kyber >= 0.0.0-0"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T09:15:05.128570230Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0289","references":[{"url":"https://crates.io/crates/pqc_kyber"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0289.html"},{"url":"https://github.com/Argyle-Software/kyber/pull/121"}],"tags":["osv","rust"],"ingestedAt":"2026-09-18T16:21:29.496Z","slug":"RUSTSEC-2026-0289","body":"## Overview\n\nThe crate has had no releases since 0.7.1 (2023-08-23), and the upstream\nrepository shows no maintainer activity. Open pull requests, including a fix for\na chosen-ciphertext key-recovery flaw in the AVX2 backend\n(Argyle-Software/kyber#121), have gone unanswered.\n\nRecommended alternatives:\n\n- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)\n- [graviola](https://crates.io/crates/graviola)\n\n## Affected packages\n\n- `pqc_kyber >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}