Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.
cvss
not scored
severity out of 10
epss
not scored
chance of exploitation in 30 days
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — RUSTSEC-2021-0059, the advisory selected below
// 1 advisories
RUSTSEC-2021-0059
UNKNOWN
Please use the aes crate going forward. The new repository location is at:
AES-NI is now autodetected at runtime on i686/x86-64 platforms. If AES-NI is not present, the aes crate will fallback to a constant-time portable software implementation.
To prevent this fallback (and have absence of AES-NI result in an illegal instruction crash instead), continue to pass the same RUSTFLAGS which were previously required for the aesni crate to compile:
RUSTFLAGS=-Ctarget-feature=+aes,+ssse3
Checked 2026-10-04 at 01:12 UTC. The most recent advisory here was published 2021-04-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.