Description
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
Scores
CVSS v3
2.9
EPSS
0.0003
EPSS Percentile
7.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (2)
crates.io/sequoia-openpgp
1.13.0 - 1.21.0crates.io
sequoia-pgp/sequoia-openpgp
1.13.0 - 1.21.0
Published
Jul 27, 2025
Tracked Since
Feb 18, 2026