<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:47:38.159641+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248622</id>
    <title>EUVD-2026-248622</title>
    <updated>2026-10-04T21:47:38.162665+00:00</updated>
    <content>EUVD-2026-248622</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58261</id>
    <title>fkie_cve-2024-58261</title>
    <updated>2026-10-04T21:47:38.162695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-58261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9344-p847-qm5c</id>
    <title>GHSA-9344-p847-qm5c — Low severity (DoS) vulnerability in sequoia-openpgp</title>
    <updated>2026-10-04T21:47:38.162725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: sequoia-openpgp</p>
<p>There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop.</p>
<p>Many thanks to Andrew Gallagher for disclosing the issue to us.</p>
<p>## Impact</p>
<p>Any software directly or indirectly using the interface `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.</p>
<p>## Details</p>
<p>The `RawCertParser` does not advance the input stream when encountering unsupported cert (primary key) versions, resulting in an infinite loop.</p>
<p>The fix introduces a new raw-cert-specific `cert::raw::Error::UnuspportedCert`.</p>
<p>## Affected software</p>
<p>- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp which is directly or indirectly using the interface sequoia_`openpgp::cert::raw::RawCertParser`.  Notably, this includes all software using the `sequoia_cert_store` crate.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9344-p847-qm5c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0345</id>
    <title>RUSTSEC-2024-0345 — Low severity (DoS) vulnerability in sequoia-openpgp</title>
    <updated>2026-10-04T21:47:38.162760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: sequoia-openpgp</p>
<p>There is a denial-of-service vulnerability in sequoia-openpgp, our
crate providing a low-level interface to our OpenPGP implementation.
When triggered, the process will enter an infinite loop.</p>
<p>Many thanks to Andrew Gallagher for disclosing the issue to us.</p>
<p>## Impact</p>
<p>Any software directly or indirectly using the interface
`sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.</p>
<p>## Details</p>
<p>The `RawCertParser` does not advance the input stream when
encountering unsupported cert (primary key) versions, resulting in an
infinite loop.</p>
<p>The fix introduces a new raw-cert-specific
`cert::raw::Error::UnuspportedCert`.</p>
<p>## Affected software</p>
<p>- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp
  which is directly or indirectly using the interface
  `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes
  all software using the `sequoia_cert_store` crate.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58261</id>
    <title>UBUNTU-CVE-2024-58261</title>
    <updated>2026-10-04T21:47:38.162790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: rust-sequoia-openpgp, Ubuntu:24.04:LTS: rust-sequoia-openpgp</p>
<p>The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58261"/>
  </entry>
</feed>
