Sequoia PGP is a Rust-based OpenPGP implementation designed as a modern alternative to traditional PGP tooling, with a narrow but security-critical footprint in cryptographic message handling and key management. Observed vulnerabilities in this vendor center on its core OpenPGP library and related components; live severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sequoia Pgp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58261HIGH The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that | Jul 27, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-2625MEDIUM A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verif | Apr 3, 2026 | 5.5 | 20 | NO | NO |
CVE-2023-53161MEDIUM The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic. | Jul 28, 2025 | 5.3 | 19 | NO | NO |
CVE-2023-53160MEDIUM The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. | Jul 28, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sequoia Pgp.
Media articles that mention a CVE ID that affects a product developed by Sequoia Pgp — matched by CVE ID, not by vendor name.