CVE-2024-58261
LOWsequoia-openpgp 1.13.0-1.20.9 - Denial of Service via RawCertParser Infinite Loop
Title source: llmDescription
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
References (3)
Core 3
Core References
Third Party Advisory
https://rustsec.org/advisories/RUSTSEC-2024-0345.html
Scores
CVSS v3
2.9
EPSS
0.0034
EPSS Percentile
26.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (2)
crates.io/sequoia-openpgp
1.13.0 - 1.21.0crates.io
sequoia-pgp/sequoia-openpgp
1.13.0 - 1.21.0
Published
Jul 27, 2025
Tracked Since
Feb 18, 2026