CVE-2024-53856

HIGH

rPGP <0.14.1 - Use After Free

Title source: llm

Description

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 50.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-148 CWE-130 CWE-617
Status draft

Affected Products (1)

crates.io/pgp < 0.14.1crates.io

Timeline

Published Dec 05, 2024
Tracked Since Feb 18, 2026