---
id: RUSTSEC-2026-0289
title: pqc_kyber is unmaintained
summary: pqc_kyber is unmaintained
severity: none
vendor: pqc_kyber
product: pqc_kyber
ecosystem: rust
affected:
  - pqc_kyber >= 0.0.0-0
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T09:15:05.128570230Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0289'
references:
  - url: 'https://crates.io/crates/pqc_kyber'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0289.html'
  - url: 'https://github.com/Argyle-Software/kyber/pull/121'
tags:
  - osv
  - rust
ingestedAt: '2026-09-18T16:21:29.496Z'
---

## Overview

The crate has had no releases since 0.7.1 (2023-08-23), and the upstream
repository shows no maintainer activity. Open pull requests, including a fix for
a chosen-ciphertext key-recovery flaw in the AVX2 backend
(Argyle-Software/kyber#121), have gone unanswered.

Recommended alternatives:

- [aws-lc-rs](https://crates.io/crates/aws-lc-rs)
- [graviola](https://crates.io/crates/graviola)

## Affected packages

- `pqc_kyber >= 0.0.0-0`

## Remediation

Refer to the advisory for the patched release.
