RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0160

pqcrypto-sphincsplus is unmaintained: upstream PQClean project being archived

Reported
Issued
Package
pqcrypto-sphincsplus (crates.io)
Type
INFO Unmaintained
References
Patched
no patched versions

Description

This crate provides Rust bindings to SPHINCS+/SLH-DSA (FIPS 205) via C implementations from PQClean. The PQClean project is being archived in or after July 2026 (see PQClean/PQClean#604), after which no further security patches or bug fixes will be applied to the upstream implementations.

As a result, this crate will no longer receive updates. Users should migrate to the slh-dsa crate, which provides a pure-Rust implementation of SLH-DSA (FIPS 205).

Advisory available under CC0-1.0 license.