—
RUSTSEC-2026-0262
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
Details
A new version of the `append-only-vec` crate was published with a direct dependency on `proc-macro1`, which would execute a malicious build script.
This compromised version was published on 2026-08-20 and removed approximately 107 minutes later, with no evidence of actual usage.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io / append-only-vec
Introduced in:
0.1.9-0 No fixed version published yet for append-only-vec. Pin to a known-safe version or switch to an alternative.