Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.
cvss
not scored
severity out of 10
epss
not scored
chance of exploitation in 30 days
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — RUSTSEC-2026-0330, the advisory selected below
// 2 advisories
RUSTSEC-2026-0330
UNKNOWN
For a hybrid KEM public key of type PublicKey::WingKemDraft06 or PublicKey::X25519MlKem768Draft06, the PublicKey::encapsulatederand function would panic in an indexing operation on a seed input of length shorter than 32 bytes.
// impact
Applications encapsulating with an attacker controlled seed value could be made to panic. Since the encapsulation seed should be considered a secret of the encapsulating party for the KEM to remain secure, an application should never take the seed value from a potentially attacker controlled source.
// mitigation
With release of version 0.0.10 of libcrux-kem this bug has been fixed and the serialization functions return InvalidPrivateKey and InvalidPublicKey errors on invalid input buffer lengths.
We recommend users upgrade to libcrux-kem version 0.0.10.
Checked 2026-10-08 at 19:33 UTC. The most recent advisory here was published 2026-09-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.