cargo package report

Is libcrux-kem safe?

2 known vulnerabilities.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.


      cvss
      not scored

      severity out of 10

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — RUSTSEC-2026-0330, the advisory selected below

      // 2 advisories

      RUSTSEC-2026-0330

      UNKNOWN

      For a hybrid KEM public key of type PublicKey::WingKemDraft06 or PublicKey::X25519MlKem768Draft06, the PublicKey::encapsulatederand function would panic in an indexing operation on a seed input of length shorter than 32 bytes.

      // impact

      Applications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.

      // mitigation

      With release of version 0.0.10 of libcrux-kem this bug has been fixed and the serialization functions return InvalidPrivateKey and InvalidPublicKey errors on invalid input buffer lengths.

      We recommend users upgrade to libcrux-kem version 0.0.10.


      Checked 2026-10-08 at 19:33 UTC. The most recent advisory here was published 2026-09-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.