VYPR
Low severityNVD Advisory· Published Jul 27, 2025· Updated Jul 28, 2025

CVE-2024-58261

CVE-2024-58261

Description

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sequoia-openpgpcrates.io
>= 1.13.0, < 1.21.01.21.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.