CVE-2024-53857: Rpgp

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

Affected products

  • Rpgp Rpgp: before 0.14.1 (fixed in 0.14.1)

Published 2024-12-05. Last modified 2026-06-17.