Sequoia Openpgp
by Sequoia Pgp
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42784 | Hig | 0.48 | 7.4 | 0.00 | Sep 16, 2026 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check.… | ||
| CVE-2024-58261 | Low | 0.19 | 2.9 | 0.00 | Jul 27, 2025 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. | ||
| CVE-2023-53160 | Low | 0.12 | 2.9 | 0.00 | Jul 28, 2025 | The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. |
- risk 0.48cvss 7.4epss 0.00
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check.…
- risk 0.19cvss 2.9epss 0.00
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
- risk 0.12cvss 2.9epss 0.00
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.