Intel

AIKIDO-2025-10617

fxhash is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 9, 2025

50

Medium Risk

This Affects:

rustfxhash
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The fxhash crate is no longer maintained, as indicated by the developer. Its last commit documents that fxhash has served its purpose and will no longer receive updates.

Who does this affect?

You are affected if you are using this package.

Background info

fxhash is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any fxhash package from your application. Please take a look at rustc-hash instead.