Intel

AIKIDO-2026-10589

core2 is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 27, 2026

50

Medium Risk

This Affects:

rustcore2
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The maintainer decided stop maintaining core2 crate and yanked all published versions.

Who does this affect?

You are affected if you are using this package.

Background info

core2 is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any core2 package from your application. Please take a look at no-std-io2 or embedded-io as an alternative.