Back to Database
Status published
Low
CVE-2024-58261
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an...
Vulnerability Description
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58261
Credits & Attribution
No credits recorded in the NVD database.
References
More from sequoia-pgp
View All →CVE-2025-67897
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext...
Medium
5.3
CVE-2023-53161
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array...
Low
2.9
CVE-2023-53160
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array...
Low
2.9
Affected Vendor
sequoia-pgp
View all reports →Affected Software
sequoia
Vulnerable Versions:
1.13.0
Timeline
Official Publish:
July 27th, 2025
Last Modified:
July 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N