CVE-2024-53857: rPGP Potential Resource Exhaustion when handling Untrusted Messages

7.5 CVSS

Description

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

Classification

CVE ID: CVE-2024-53857

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

Affected Products

Vendor: rpgp

Product: rpgp

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/rpgp/rpgp/security/advisories/GHSA-4grw-m28r-q285

Timeline