<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:47:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-248622</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248622</link>
      <description>EUVD-2026-248622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248622</guid>
    </item>
    <item>
      <title>fkie_cve-2024-58261</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58261</link>
      <description>&lt;p&gt;The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of &amp;#34;Reading a cert: Invalid operation: Not a Key packet&amp;#34; messages for RawCertParser operations that encounter an unsupported primary key type.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of &amp;#34;Reading a cert: Invalid operation: Not a Key packet&amp;#34; messages for RawCertParser operations that encounter an unsupported primary key type.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-58261</guid>
    </item>
    <item>
      <title>GHSA-9344-p847-qm5c — Low severity (DoS) vulnerability in sequoia-openpgp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9344-p847-qm5c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sequoia-openpgp&lt;/p&gt;
&lt;p&gt;There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop.&lt;/p&gt;
&lt;p&gt;Many thanks to Andrew Gallagher for disclosing the issue to us.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any software directly or indirectly using the interface `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `RawCertParser` does not advance the input stream when encountering unsupported cert (primary key) versions, resulting in an infinite loop.&lt;/p&gt;
&lt;p&gt;The fix introduces a new raw-cert-specific `cert::raw::Error::UnuspportedCert`.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp which is directly or indirectly using the interface sequoia_`openpgp::cert::raw::RawCertParser`.  Notably, this includes all software using the `sequoia_cert_store` crate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sequoia-openpgp&lt;/p&gt;
&lt;p&gt;There is a denial-of-service vulnerability in sequoia-openpgp, our crate providing a low-level interface to our OpenPGP implementation. When triggered, the process will enter an infinite loop.&lt;/p&gt;
&lt;p&gt;Many thanks to Andrew Gallagher for disclosing the issue to us.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any software directly or indirectly using the interface `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `RawCertParser` does not advance the input stream when encountering unsupported cert (primary key) versions, resulting in an infinite loop.&lt;/p&gt;
&lt;p&gt;The fix introduces a new raw-cert-specific `cert::raw::Error::UnuspportedCert`.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp which is directly or indirectly using the interface sequoia_`openpgp::cert::raw::RawCertParser`.  Notably, this includes all software using the `sequoia_cert_store` crate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9344-p847-qm5c</guid>
    </item>
    <item>
      <title>RUSTSEC-2024-0345 — Low severity (DoS) vulnerability in sequoia-openpgp</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2024-0345</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sequoia-openpgp&lt;/p&gt;
&lt;p&gt;There is a denial-of-service vulnerability in sequoia-openpgp, our
crate providing a low-level interface to our OpenPGP implementation.
When triggered, the process will enter an infinite loop.&lt;/p&gt;
&lt;p&gt;Many thanks to Andrew Gallagher for disclosing the issue to us.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any software directly or indirectly using the interface
`sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `RawCertParser` does not advance the input stream when
encountering unsupported cert (primary key) versions, resulting in an
infinite loop.&lt;/p&gt;
&lt;p&gt;The fix introduces a new raw-cert-specific
`cert::raw::Error::UnuspportedCert`.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp
  which is directly or indirectly using the interface
  `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes
  all software using the `sequoia_cert_store` crate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: sequoia-openpgp&lt;/p&gt;
&lt;p&gt;There is a denial-of-service vulnerability in sequoia-openpgp, our
crate providing a low-level interface to our OpenPGP implementation.
When triggered, the process will enter an infinite loop.&lt;/p&gt;
&lt;p&gt;Many thanks to Andrew Gallagher for disclosing the issue to us.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any software directly or indirectly using the interface
`sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes all
software using the `sequoia_cert_store` crate.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `RawCertParser` does not advance the input stream when
encountering unsupported cert (primary key) versions, resulting in an
infinite loop.&lt;/p&gt;
&lt;p&gt;The fix introduces a new raw-cert-specific
`cert::raw::Error::UnuspportedCert`.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- sequoia-openpgp 1.13.0
- sequoia-openpgp 1.14.0
- sequoia-openpgp 1.15.0
- sequoia-openpgp 1.16.0
- sequoia-openpgp 1.17.0
- sequoia-openpgp 1.18.0
- sequoia-openpgp 1.19.0
- sequoia-openpgp 1.20.0
- Any software built against a vulnerable version of sequoia-openpgp
  which is directly or indirectly using the interface
  `sequoia_openpgp::cert::raw::RawCertParser`.  Notably, this includes
  all software using the `sequoia_cert_store` crate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2024-0345</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-58261</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58261</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: rust-sequoia-openpgp, Ubuntu:24.04:LTS: rust-sequoia-openpgp&lt;/p&gt;
&lt;p&gt;The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of &amp;#34;Reading a cert: Invalid operation: Not a Key packet&amp;#34; messages for RawCertParser operations that encounter an unsupported primary key type.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: rust-sequoia-openpgp, Ubuntu:24.04:LTS: rust-sequoia-openpgp&lt;/p&gt;
&lt;p&gt;The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of &amp;#34;Reading a cert: Invalid operation: Not a Key packet&amp;#34; messages for RawCertParser operations that encounter an unsupported primary key type.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58261</guid>
    </item>
  </channel>
</rss>
