Vulnerabilities
Vulnerable Software
Sequoia-Pgp:  Security Vulnerabilities
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can trigger an error in the OpenPGP signature parsing code, leading to an unconditional termination of the rpm process. This issue results in an application level denial of service, making the system unable to process RPM files for signature verification.
CVSS Score
4.0
EPSS Score
0.0
Published
2026-04-03
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVSS Score
2.9
EPSS Score
0.001
Published
2025-07-28
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
CVSS Score
2.9
EPSS Score
0.001
Published
2025-07-28
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
CVSS Score
2.9
EPSS Score
0.0
Published
2025-07-27


Contact Us

Shodan ® - All rights reserved