---
id: RUSTSEC-2026-0287
title: cosmian_kyber is unmaintained
summary: cosmian_kyber is unmaintained
severity: none
vendor: cosmian_kyber
product: cosmian_kyber
ecosystem: rust
affected:
  - cosmian_kyber >= 0.0.0-0
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T09:15:05.147975858Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0287'
references:
  - url: 'https://crates.io/crates/cosmian_kyber'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0287.html'
  - url: 'https://github.com/Cosmian/kyber/pull/6'
tags:
  - osv
  - rust
ingestedAt: '2026-09-18T16:21:29.496Z'
---

## Overview

`cosmian_kyber` is a fork of `Argyle-Software/kyber` that has seen no maintainer
activity. It inherits the fork parent's broken AVX2 constant-time code, and the
open fix pull request (Cosmian/kyber#6) has gone unanswered.

Recommended alternatives:

- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)
- [graviola](https://crates.io/crates/graviola)

## Affected packages

- `cosmian_kyber >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
