{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sequoia-openpgp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sequoia-pgp:sequoia-openpgp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-42784"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["sequoia-openpgp"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Sequoia PGP"],"content_html":"\u003cp\u003eA cryptographic vulnerability (CVE-2026-42784) affects the sequoia-openpgp library, specifically regarding how it handles older OpenPGP certificates. The issue arises when a certificate lacks a key flags subpacket. In these instances, the library incorrectly infers key flags, creating a discrepancy in the assumed capabilities of the certificate. This flaw permits an attacker to bypass the back-signature check, a critical mechanism for verifying the legitimacy of subkey bindings. By exploiting this discrepancy, an attacker can bind arbitrary subkeys to their own certificates and forge signatures that appear valid to systems relying on the affected library. This failure compromises the integrity of cryptographic operations, potentially allowing for unauthorized data access or the impersonation of trusted entities within systems utilizing sequoia-openpgp for certificate validation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation compromises cryptographic integrity, allowing for subkey binding forgery and signature spoofing. This affects any application or system leveraging the sequoia-openpgp library for parsing and validating legacy OpenPGP certificates, potentially leading to unauthorized data decryption or identity masquerading.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all software and services within the infrastructure that utilize the sequoia-openpgp library.\u003c/li\u003e\n\u003cli\u003eMonitor vendor security advisories and the official Sequoia PGP release channels for patch availability related to CVE-2026-42784.\u003c/li\u003e\n\u003cli\u003ePrioritize updating affected applications to the patched version once released to mitigate the risk of signature forgery.\u003c/li\u003e\n\u003cli\u003eConduct a review of cryptographic validation logic in high-assurance systems to identify dependencies on sequoia-openpgp until the vulnerability is addressed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T17:52:06Z","date_published":"2026-09-16T17:52:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sequoia-openpgp-vulnerability/","summary":"A vulnerability in the sequoia-openpgp library allows attackers to bypass back-signature checks and forge subkey bindings due to incorrect key flag inference.","title":"Cryptographic Vulnerability in sequoia-openpgp","url":"https://feed.craftedsignal.io/briefs/2026-09-sequoia-openpgp-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Sequoia-Openpgp","version":"https://jsonfeed.org/version/1.1"}