Low severity2.9NVD Advisory· Published Jul 27, 2025· Updated Jun 17, 2026
CVE-2024-58261
CVE-2024-58261
Description
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sequoia-openpgpcrates.io | >= 1.13.0, < 1.21.0 | 1.21.0 |
Affected products
3- cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:*Range: >=1.13.0,<1.21.0
- Range: 1.13.0
Patches
Vulnerability mechanics
References
5- gitlab.com/sequoia-pgp/sequoia/-/issues/1106nvdExploitWEB
- github.com/advisories/GHSA-9344-p847-qm5cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-58261ghsaADVISORY
- rustsec.org/advisories/RUSTSEC-2024-0345.htmlnvdThird Party AdvisoryWEB
- crates.io/crates/sequoia-openpgpnvdProduct
News mentions
0No linked articles in our index yet.