Openpgpjs is a JavaScript implementation of the OpenPGP standard for encryption and digital signature operations, embedded in web applications and browser extensions that handle sensitive cryptographic workflows. The vendor's disclosed vulnerabilities center on its core cryptographic functions, clustering around signature-verification logic and the use of weak or deprecated cryptographic algorithms, reflecting the complexity of maintaining standards-compliant encryption in a dynamic web environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpgpjs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-8013HIGH s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is u | Jul 25, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-9155MEDIUM A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct | Aug 22, 2019 | 5.9 | 21 | NO | NO |
CVE-2019-9153HIGH Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" | Aug 22, 2019 | 7.5 | 20 | NO | NO |
CVE-2019-9154HIGH Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed. | Aug 22, 2019 | 7.5 | 19 | NO | NO |
CVE-2023-41037MEDIUM OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed tex | Aug 29, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpgpjs.
Media articles that mention a CVE ID that affects a product developed by Openpgpjs — matched by CVE ID, not by vendor name.