CVE-2023-53160
LOWSequoia-pgp Sequoia-openpgp < 1.1.1 - Out-of-Bounds Read
Title source: ruleDescription
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
References (4)
Core 4
Core References
Third Party Advisory
https://github.com/advisories/GHSA-25mx-8f3v-8wh7
Third Party Advisory
https://rustsec.org/advisories/RUSTSEC-2023-0038.html
Scores
CVSS v3
2.9
EPSS
0.0007
EPSS Percentile
21.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (2)
crates.io/sequoia-openpgp
0 - 1.1.1crates.io
sequoia-pgp/sequoia-openpgp
< 1.1.1
Published
Jul 28, 2025
Tracked Since
Feb 18, 2026