VYPR

sequoia-openpgp

by Red Hat

CVEs (1)

  • CVE-2026-42784HigSep 16, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check.…