Out-of-Bounds Array Access in Sequoia OpenPGP for Rust
CVE-2023-53160

2.9LOW

Key Information:

Status
Vendor
CVE Published:
28 July 2025

What is CVE-2023-53160?

The Sequoia OpenPGP crate prior to version 1.16.0 for the Rust programming language is susceptible to a vulnerability that allows for out-of-bounds array access, which may lead to program panics. This issue can potentially disrupt the normal functioning of applications that rely on this crate, underscoring the importance of updating to the latest version for developers using Sequoia OpenPGP in their projects.

Affected Version(s)

sequoia 0 < 1.1.1

sequoia 1.2.0 < 1.8.1

sequoia 1.9.0 < 1.16.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.