Junglewise Threat Intelligence

cosmian_kyber unmaintained library

Severity: info · Published 2026-09-17

Vendors: crates.io.

Executive brief

cosmian_kyber is a Rust library implementing the post-quantum Kyber cryptographic algorithm that is no longer maintained by its developers. The library inherits broken constant-time code from its parent project, leaving it vulnerable to timing attacks and exposing applications that depend on it to potential cryptographic weaknesses.

Technical details

cosmian_kyber is an unmaintained fork of Argyle-Software/kyber that carries forward a broken AVX2 constant-time implementation inherited from its parent. An open pull request addressing this vulnerability (Cosmian/kyber#6) remains unmerged with no maintainer response. Applications using this library for post-quantum key encapsulation may be susceptible to timing-based side-channel attacks.

Affected products

  • Cosmian cosmian_kyber all versions

Timeline

  • 2026-09-17: disclosed: Advisory published

References

Related threats