| Release | Version |
|---|---|
| bookworm | 1.12.0-2 |
| trixie | 2.0.0-2+deb13u1 |
| forky | 2.4.1-1 |
| sid | 2.4.1-1 |
| Bug | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|
| CVE-2026-42784 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | openpgp: Don't imply missing key flags from key type |
| CVE-2026-42783 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | openpgp: Reject nested embedded signatures |
| CVE-2025-67897 | vulnerable (no DSA) | fixed | fixed | fixed | In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext ... |
| CVE-2023-53160 | vulnerable (no DSA) | fixed | fixed | fixed | The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds ... |
| Bug | Description |
|---|---|
| CVE-2024-58261 | The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infi ... |