Intel

AIKIDO-2026-648521

libcrux-aesgcm is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Today

80

High Risk

This Affects:

Are you affected? Scan for Free

TL;DR

The libcrux-aesgcm crate has been renamed to libcrux-aes and is no longer maintained, with version 0.0.8 being the final release under the old name. Development continues in libcrux-aes starting from version 0.0.9. Because libcrux-aesgcm is unmaintained and vulnerabilities have already been identified in the discontinued crate, users should migrate to libcrux-aes to receive security fixes and future updates.

Who does this affect?

You are affected if you are using this package.

Background info

libcrux-aesgcm is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any libcrux-aesgcm package from your application. Please take a look at libcrux-aes as an alternative.