sequoia-openpgp
Activity
- Latest release
- 2mo ago
- Total releases
- 60
- Cadence
- ~42 days
- Last 12 months
- 6
Details
- License
- LGPL-2.0-or-later
- First release
- Nov 24, 2018
| Version | Released | |
|---|---|---|
2.4.1
unknown
|
2.4.1
unknown
Dependencies (70)
+ 62 more |
|
2.4.0
unknown
|
2.4.0
unknown
Dependencies (68)
+ 60 more |
|
2.3.0
unknown
|
2.3.0
unknown
Dependencies (66)
+ 58 more |
|
2.2.0
unknown
|
2.2.0
unknown
Dependencies (63)
+ 55 more |
|
2.2.0-pqc.1
unknown
|
2.2.0-pqc.1
unknown
Dependencies (62)
+ 54 more |
|
2.1.0
unknown
|
2.1.0
unknown
Dependencies (63)
+ 55 more |
|
2.0.0
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0
unknown
Dependencies (62)
+ 54 more |
|
2.0.0-alpha.2
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.2
unknown
Dependencies (62)
+ 54 more |
|
2.0.0-alpha.1
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.1
unknown
Dependencies (65)
+ 57 more |
|
2.0.0-alpha.0
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.0
unknown
Dependencies (65)
+ 57 more |
|
1.22.0
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.22.0
unknown
Dependencies (60)
+ 52 more |
|
1.21.2
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.21.2
unknown
Dependencies (60)
+ 52 more |
|
1.21.1
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.21.1
unknown
Dependencies (60)
+ 52 more |
|
1.21.0
unknown
yanked
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.21.0
unknown
yanked
Dependencies (60)
+ 52 more |
|
1.20.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.20.0
unknown
Dependencies (58)
+ 50 more |
|
1.19.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.19.0
unknown
Dependencies (58)
+ 50 more |
|
1.18.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.18.0
unknown
Dependencies (58)
+ 50 more |
|
1.17.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.17.0
unknown
Dependencies (57)
+ 49 more |
|
1.16.1
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.16.1
unknown
Dependencies (57)
+ 49 more |
|
1.8.1
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.8.1
unknown
Dependencies (53)
+ 45 more |
|
1.1.1
unknown
1 CVE
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.1.1
unknown
Dependencies (28)
+ 20 more |
|
1.16.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev |
1.16.0
unknown
Dependencies (57)
+ 49 more |
|
1.15.0
unknown
3 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.15.0
unknown
Dependencies (57)
+ 49 more |
|
1.14.0
unknown
3 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.14.0
unknown
Dependencies (56)
+ 48 more |
|
1.13.0
unknown
3 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-58261
GHSA-9344-p847-qm5c
RUSTSEC-2024-0345
Jun 26, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop. Many thanks to Andrew Gallagher for disclosing the issue to us. ImpactAny software directly or indirectly using the interface DetailsThe The fix introduces a new raw-cert-specific Affected software
Fixed in
1.21.0
References Updated Oct 28, 2025 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.13.0
unknown
Dependencies (54)
+ 46 more |
|
1.12.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.12.0
unknown
Dependencies (51)
+ 43 more |
|
1.11.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.11.0
unknown
Dependencies (51)
+ 43 more |
|
1.10.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.10.0
unknown
Dependencies (51)
+ 43 more |
|
1.9.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.9.0
unknown
Dependencies (51)
+ 43 more |
|
1.8.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.8.0
unknown
Dependencies (53)
+ 45 more |
|
1.7.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.7.0
unknown
Dependencies (53)
+ 45 more |
|
1.6.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.6.0
unknown
Dependencies (51)
+ 43 more |
|
1.5.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.5.0
unknown
Dependencies (50)
+ 42 more |
|
1.4.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.4.0
unknown
Dependencies (51)
+ 43 more |
|
1.3.1
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.3.1
unknown
Dependencies (29)
+ 21 more |
|
1.3.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.3.0
unknown
Dependencies (29)
+ 21 more |
|
1.1.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.1.0
unknown
Dependencies (28)
+ 20 more |
|
1.0.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
1.0.0
unknown
Dependencies (27)
+ 19 more |
|
0.21.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.21.0
unknown
Dependencies (27)
+ 19 more |
|
0.20.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.20.0
unknown
Dependencies (24)
+ 16 more |
|
0.19.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.19.0
unknown
Dependencies (26)
+ 18 more |
|
0.18.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.18.0
unknown
Dependencies (22)
+ 14 more |
|
0.17.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.17.0
unknown
Dependencies (21)
+ 13 more |
|
0.16.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.16.0
unknown
Dependencies (18)
+ 10 more |
|
0.15.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.15.0
unknown
Dependencies (16)
+ 8 more |
|
0.14.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.14.0
unknown
Dependencies (16)
+ 8 more |
|
0.13.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.13.0
unknown
Dependencies (16)
+ 8 more |
|
0.12.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.12.0
unknown
Dependencies (15)
+ 7 more |
|
0.11.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.11.0
unknown
Dependencies (15)
+ 7 more |
|
0.10.0
unknown
2 CVEs
CVE-2025-67897
GHSA-v6x3-9r38-r27q
RUSTSEC-2025-0136
Dec 14, 2025
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Fixed in
2.1.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-53160
GHSA-25mx-8f3v-8wh7
RUSTSEC-2023-0038
Jun 06, 2023
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
2.9
/ 10
Low
Local
High
None
None
Unchanged
None
None
Low
Affected versions of the crate have several bugs where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space. Fixed in
1.1.1
1.8.1
1.16.0
References
Updated Jul 28, 2025 · Source: OSV.dev |
0.10.0
unknown
Dependencies (16)
+ 8 more |