{"id":"GHSA-c7ph-f7jm-xv4w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c7ph-f7jm-xv4w","summary":"rPGP's integrity protection of encrypted data was not always checked","details":"### Summary\nFor some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid.\n\n### Details\nWhen decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library.\n\n### Impact\nWhile the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it.\n\n### Attribution\nDiscovered internally in the course of rPGP development work.","published":"2026-02-13T20:55:20Z","modified":"2026-02-22T23:23:41.778238Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"pgp","fixedVersion":"0.19.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rpgp/rpgp/security/advisories/GHSA-c7ph-f7jm-xv4w"},{"type":"PACKAGE","url":"https://github.com/rpgp/rpgp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-22T23:23:41.778238Z"}}