mediumVulnerability
GHSA-c7ph-f7jm-xv4w
### Summary For some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid. ### Details When decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library. ### Impact While the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it. ### Attribution Discovered internally in the course of rPGP development work.
Properties
- ghsa_id
- GHSA-c7ph-f7jm-xv4w
- severity
- medium
- summary
- rPGP's integrity protection of encrypted data was not always checked
- cve_id
- GHSA-c7ph-f7jm-xv4w
- is_ghsa_only
- true
- ghsa_published
- 2026-02-13T20:55:20Z
- source_url
- https://github.com/advisories/GHSA-c7ph-f7jm-xv4w
- ghsa_updated
- 2026-02-13T20:55:21Z
Related Entities (3)
AFFECTS (1)
→[Software]rust/pgp
HAS_WEAKNESS (1)
→[Weakness]Improper Validation of Integrity Check Value
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph