<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:sequoia-Pgp:sequoia-Openpgp:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asequoia-pgpsequoia-openpgp/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 17:52:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asequoia-pgpsequoia-openpgp/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cryptographic Vulnerability in sequoia-openpgp</title><link>https://feed.craftedsignal.io/briefs/2026-09-sequoia-openpgp-vulnerability/</link><pubDate>Wed, 16 Sep 2026 17:52:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sequoia-openpgp-vulnerability/</guid><description>A vulnerability in the sequoia-openpgp library allows attackers to bypass back-signature checks and forge subkey bindings due to incorrect key flag inference.</description><content:encoded><![CDATA[<p>A cryptographic vulnerability (CVE-2026-42784) affects the sequoia-openpgp library, specifically regarding how it handles older OpenPGP certificates. The issue arises when a certificate lacks a key flags subpacket. In these instances, the library incorrectly infers key flags, creating a discrepancy in the assumed capabilities of the certificate. This flaw permits an attacker to bypass the back-signature check, a critical mechanism for verifying the legitimacy of subkey bindings. By exploiting this discrepancy, an attacker can bind arbitrary subkeys to their own certificates and forge signatures that appear valid to systems relying on the affected library. This failure compromises the integrity of cryptographic operations, potentially allowing for unauthorized data access or the impersonation of trusted entities within systems utilizing sequoia-openpgp for certificate validation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation compromises cryptographic integrity, allowing for subkey binding forgery and signature spoofing. This affects any application or system leveraging the sequoia-openpgp library for parsing and validating legacy OpenPGP certificates, potentially leading to unauthorized data decryption or identity masquerading.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all software and services within the infrastructure that utilize the sequoia-openpgp library.</li>
<li>Monitor vendor security advisories and the official Sequoia PGP release channels for patch availability related to CVE-2026-42784.</li>
<li>Prioritize updating affected applications to the patched version once released to mitigate the risk of signature forgery.</li>
<li>Conduct a review of cryptographic validation logic in high-assurance systems to identify dependencies on sequoia-openpgp until the vulnerability is addressed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>