CVE-2024-58261: Sequoia-Pgp Sequoia-Openpgp
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
Affected products
- Sequoia-Pgp Sequoia-Openpgp: from 1.13.0, before 1.21.0 (fixed in 1.21.0)
Published 2025-07-27. Last modified 2026-06-17.