Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.
cvss
not scored
severity out of 10
epss
not scored
chance of exploitation in 30 days
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — RUSTSEC-2026-0329, the advisory selected below
// 1 advisories
RUSTSEC-2026-0329
UNKNOWN
The automatically reseeding implementations of HMAC-DRBG would panic if called with a desired non-zero output length cleanly divisible by 65536, the maximum number of output bytes that can be generated before reseeding has to happen.
// impact
An application relying on libcrux-hmac-drgb to provide randomness of byte length a non-zero integer multiple of 65536 in a single call to fillbytes would panic.
Any calls with output buffer lengths not cleanly divisible by 65536 are not affected.
// mitigation
With release the release of version 0.0.2 of libcrux-hmac-drbg this bug has been fixed and reseeding DRBG implementations can be used with arbitrary output lengths.
We recommend users upgrade to libcrux-hmac-drbg version 0.0.2.
Checked 2026-10-08 at 19:33 UTC. The most recent advisory here was published 2026-08-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.