CVE-2026-42784: Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion

Published Sep 16, 2026
·
Updated

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.

Affected Software

1 affected component
sequoia-openpgp

Event History

Sep 16, 2026
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which certificates are affected by the key flag confusion?

The issue affects older certificates where the key flags subpacket is missing. The library incorrectly infers capabilities for those certificates, creating a discrepancy in key capability handling.

2

What does an attacker need to do to exploit this flaw?

An attacker needs to exploit the capability discrepancy to bypass the back-signature check. This allows them to bind an arbitrary subkey to their own certificate and forge signatures.

3

What is the practical security impact?

Successful exploitation completely compromises cryptographic integrity. Forged signatures may be accepted because an attacker can illegitimately attach a subkey to their certificate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203