CVE-2024-58261
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2025
Last modified:
06/08/2025
Description
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
Impact
Base Score 3.x
2.90
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:rust:*:* | 1.13.0 (including) | 1.21.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



