Description
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Published: 2026-09-16
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Cryptographic integrity compromise
Action: Assess Impact
AI Analysis

Impact

An error in the sequoia-openpgp library misinterprets key flags when a key‑flags subpacket is missing. The result is that the library presents an attacker‑controlled key’s capabilities as if they were legitimate, allowing the attacker to bypass the back‑signature check. The attacker can then bind an arbitrary subkey to their own certificate and forge signatures, entirely compromising cryptographic integrity. The weakness is classified as CWE‑347, a subtle logic error in credential handling. The CVSS score of 7.4 indicates a high severity vulnerability, with potential to disrupt trust chains or invalidate data authenticity if exploited by an adversary with the ability to supply forged certificates.

Affected Systems

Red Hat products that incorporate sequoia-openpgp are affected, including Red Hat Ansible Automation Platform 2, Red Hat Confidential Compute Attestation, Red Hat Enterprise Linux 9 and 10, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Trusted Profile Analyzer and Red Hat Hardened Images. No specific version information is provided, so all current and older supported releases that include the sequoia‑openpgp library may be vulnerable.

Risk and Exploitability

The EPSS score of less than 1% suggests exploitation is currently unlikely, but the risk is non‑zero and the vulnerability is still listed in public databases. Because the flaw requires the attacker to supply a forged certificate or subkey that the target system will parse, the likely attack vector involves credential injection or malicious content delivered to a signing service. Once the back‑signature check is bypassed, an attacker could generate signatures that appear valid, leading to unauthorized data acceptance or replay attacks. The vulnerability is not yet listed in CISA KEV, indicating no publicly documented trusted exploit, yet the high CVSS score warrants vigilance.

Generated by OpenCVE AI on September 18, 2026 at 01:10 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any available vendor updates for the affected Red Hat products that contain a fix for sequoia‑openpgp.
  • If a patch is not immediately available, limit or disable the use of sequoia‑open‑pgp‑based signing operations in production environments. In the meantime enforce strict certificate validation that requires a key‑flags subpacket and reject certificates lacking it.
  • Enable detailed logging for all signature validation events and monitor logs for anomalous signatures or back‑signature bypass attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 18, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
References

Tue, 06 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
References

Tue, 06 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::crb
cpe:/o:redhat:enterprise_linux:9::baseos
References

Tue, 06 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Mon, 21 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
References

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat enterprise Linux
Redhat hardened Images
Redhat openshift Container Platform
Redhat satellite 6
Sequoia-pgp
Sequoia-pgp sequoia-openpgp
Vendors & Products Red Hat
Red Hat enterprise Linux
Redhat hardened Images
Redhat openshift Container Platform
Redhat satellite 6
Sequoia-pgp
Sequoia-pgp sequoia-openpgp

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.
Title Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion
First Time appeared Redhat
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat satellite
Redhat trusted Profile Analyzer
Weaknesses CWE-347
CPEs cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:confidential_compute_attestation:1
cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/a:redhat:satellite:6
cpe:/a:redhat:trusted_profile_analyzer:2
cpe:/a:redhat:trusted_profile_analyzer:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat satellite
Redhat trusted Profile Analyzer
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


Subscriptions

Red Hat Enterprise Linux
Redhat Ansible Automation Platform Confidential Compute Attestation Enterprise Linux Hardened Images Hummingbird Openshift Openshift Container Platform Satellite Satellite 6 Trusted Profile Analyzer
Sequoia-pgp Sequoia-openpgp
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T15:45:49.469Z

Reserved: 2026-04-29T15:09:53.696Z

Link: CVE-2026-42784

cve-icon Vulnrichment

Updated: 2026-09-18T18:12:24.733Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:17:18.380

Modified: 2026-10-07T16:17:47.963

Link: CVE-2026-42784

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-42784 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:31Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature