{"id":"GHSA-c7ph-f7jm-xv4w","summary":"rPGP's integrity protection of encrypted data was not always checked","details":"### Summary\nFor some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid.\n\n### Details\nWhen decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library.\n\n### Impact\nWhile the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it.\n\n### Attribution\nDiscovered internally in the course of rPGP development work.","modified":"2026-02-22T23:23:41.778238Z","published":"2026-02-13T20:55:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-02-13T20:55:20Z","nvd_published_at":null,"cwe_ids":["CWE-354"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/rpgp/rpgp/security/advisories/GHSA-c7ph-f7jm-xv4w"},{"type":"PACKAGE","url":"https://github.com/rpgp/rpgp"}],"affected":[{"package":{"name":"pgp","ecosystem":"crates.io","purl":"pkg:cargo/pgp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.16.0-alpha.0"},{"fixed":"0.19.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-c7ph-f7jm-xv4w/GHSA-c7ph-f7jm-xv4w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}