RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0164

pqcrypto is unmaintained: upstream PQClean project being archived

Reported
Issued
Package
pqcrypto (crates.io)
Type
INFO Unmaintained
References
Patched
no patched versions

Description

The pqcrypto crate and the entire pqcrypto-* ecosystem wrap C implementations from PQClean. The PQClean project is being archived in or after July 2026 (see PQClean/PQClean#604), after which no further security patches, algorithm updates, or bug fixes will be applied to the upstream implementations.

As a result, this crate and all dependent crates in the pqcrypto-* ecosystem will no longer receive updates. Users should migrate to actively maintained alternatives. Pure-Rust replacements are available for several algorithms:

Advisory available under CC0-1.0 license.