Sequoia Pgp
Products
4- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-67897 | Med | 0.34 | 5.3 | 0.00 | Dec 14, 2025 | In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. | ||
| CVE-2026-2625 | Med | 0.26 | 4.0 | 0.00 | Apr 3, 2026 | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code,… | ||
| CVE-2024-58261 | Low | 0.19 | 2.9 | 0.00 | Jul 27, 2025 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. | ||
| CVE-2023-53161 | Low | 0.12 | 2.9 | 0.00 | Jul 28, 2025 | The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic. | ||
| CVE-2023-53160 | Low | 0.12 | 2.9 | 0.00 | Jul 28, 2025 | The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. |
- risk 0.34cvss 5.3epss 0.00
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.
- risk 0.26cvss 4.0epss 0.00
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code,…
- risk 0.19cvss 2.9epss 0.00
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
- risk 0.12cvss 2.9epss 0.00
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
- risk 0.12cvss 2.9epss 0.00
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.