Description
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Published: 2026-09-16
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat enterprise Linux
Redhat hardened Images
Redhat openshift Container Platform
Redhat satellite 6
Sequoia-pgp
Sequoia-pgp sequoia-openpgp
Vendors & Products Red Hat
Red Hat enterprise Linux
Redhat hardened Images
Redhat openshift Container Platform
Redhat satellite 6
Sequoia-pgp
Sequoia-pgp sequoia-openpgp

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Title Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion
First Time appeared Redhat
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat satellite
Redhat trusted Profile Analyzer
Weaknesses CWE-347
CPEs cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:confidential_compute_attestation:1
cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/a:redhat:satellite:6
cpe:/a:redhat:trusted_profile_analyzer:2
cpe:/a:redhat:trusted_profile_analyzer:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat satellite
Redhat trusted Profile Analyzer
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


Subscriptions

Red Hat Enterprise Linux
Redhat Ansible Automation Platform Confidential Compute Attestation Enterprise Linux Hardened Images Hummingbird Openshift Openshift Container Platform Satellite Satellite 6 Trusted Profile Analyzer
Sequoia-pgp Sequoia-openpgp
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T18:12:29.708Z

Reserved: 2026-04-29T15:09:53.696Z

Link: CVE-2026-42784

cve-icon Vulnrichment

Updated: 2026-09-18T18:12:24.733Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:18.380

Modified: 2026-09-18T18:17:06.793

Link: CVE-2026-42784

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-42784 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:31Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature