highVulnerability

GHSA-8h58-w33p-wq3g

### Summary Previous rPGP versions could be caused to crash with a "stack overflow" when parsing messages that contain deeply nested message layers, such as messages with many signatures. rPGP 0.19.0 resolves this issue with a more robust message handling implementation (via https://github.com/rpgp/rpgp/pull/625). ### Impact An attacker could cause applications to crash in rPGP's message parsing subsystem, when applications attempt to ingest messages. ### Attribution Discovered internally during rPGP development, using a fuzz test suite previously contributed by Christian Reitter.

Properties

ghsa_id
GHSA-8h58-w33p-wq3g
severity
high
summary
rPGP affected by crash in message handling for deeply nested messages
cve_id
GHSA-8h58-w33p-wq3g
is_ghsa_only
true
ghsa_published
2026-02-13T20:54:27Z
source_url
https://github.com/advisories/GHSA-8h58-w33p-wq3g
ghsa_updated
2026-02-13T20:54:28Z

Related Entities (3)

AFFECTS (1)

[Software]rust/pgp

HAS_WEAKNESS (1)

[Weakness]Stack-based Buffer Overflow

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph