cargo package report

Is libcrux-hmac-drbg safe?

1 known vulnerability.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.


      cvss
      not scored

      severity out of 10

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — RUSTSEC-2026-0329, the advisory selected below

      // 1 advisories

      RUSTSEC-2026-0329

      UNKNOWN

      The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65536, the maximum number of output bytes that can be generated before reseeding has to happen.

      // impact

      An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65536 in a single call to fillbytes would panic.

      Any calls with output buffer lengths not cleanly divisible by 65536 are not affected.

      // mitigation

      With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.

      We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.


      Checked 2026-10-08 at 19:33 UTC. The most recent advisory here was published 2026-08-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.