Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp
Low severity
GitHub Reviewed
Published
Jul 27, 2025
to the GitHub Advisory Database
•
Updated Jul 28, 2025
Withdrawn
This advisory was withdrawn on Jul 28, 2025
Description
Published by the National Vulnerability Database
Jul 27, 2025
Published to the GitHub Advisory Database
Jul 27, 2025
Reviewed
Jul 28, 2025
Withdrawn
Jul 28, 2025
Last updated
Jul 28, 2025
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-9344-p847-qm5c. This link is maintained to preserve external references.
Original Description
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
References