mediumVulnerability

GHSA-c7ph-f7jm-xv4w

### Summary For some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid. ### Details When decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library. ### Impact While the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it. ### Attribution Discovered internally in the course of rPGP development work.

Properties

ghsa_id
GHSA-c7ph-f7jm-xv4w
severity
medium
summary
rPGP's integrity protection of encrypted data was not always checked
cve_id
GHSA-c7ph-f7jm-xv4w
is_ghsa_only
true
ghsa_published
2026-02-13T20:55:20Z
source_url
https://github.com/advisories/GHSA-c7ph-f7jm-xv4w
ghsa_updated
2026-02-13T20:55:21Z

Related Entities (3)

AFFECTS (1)

[Software]rust/pgp

HAS_WEAKNESS (1)

[Weakness]Improper Validation of Integrity Check Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph