Skip to content
CVE Alert: CVE-2026-42784 – Red Hat

CVE Alert: CVE-2026-42784 – Red Hat

Redpacketsecurity admin September 17, 2026

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, completely compromising cryptographic integrity.

## AI Summary Analysis

**Risk verdict:** High-priority cryptographic integrity risk requiring prompt remediation, although exploitation status cannot be confirmed because KEV, SSVC and EPSS data are not provided.

**Why this matters:** Successful abuse could make unauthorised data, software or infrastructure actions appear properly signed, undermining trust decisions rather than merely causing a local service fault. Likely attacker objectives include tampering with automation content, substituting packages or images, and weakening attestation or supply-chain controls. The principal business risk is silent acceptance of fraudulent artefacts and delayed detection of compromise.

**Most likely attack path:** The network-reachable, low-complexity path requires no privileges, but does require a user or service to process attacker-controlled key material, certificates or signed content. Scope change means a successful forgery could influence other components that rely on the affected verification result, enabling downstream compromise or lateral movement through trusted automation and deployment workflows.

**Who is most exposed:** Organisations using automated build, package, container, repository, attestation or configuration-management pipelines are most at risk. Exposure is greatest where externally supplied certificates or artefacts are verified by affected libraries in shared management or cluster-control services.

Alert on signatures accepted from newly introduced or unexpected subkeys.

Compare certificate key capabilities and back-signature validation across independent tooling.

Review package, image and automation changes lacking an expected signer or provenance.

Hunt for verification failures followed by successful acceptance of the same artefact.

Audit attestation and repository logs for anomalous signer changes.

Mitigation and prioritisation:

Apply the vendor’s corrected packages as soon as operationally feasible; treat as an urgent security update.

Until patched, restrict ingestion of untrusted certificates and signed artefacts at repository and pipeline boundaries.

Require independent signature verification for high-impact deployments and release approvals.

Coordinate staged rollout and revalidation of trusted keys, packages and images; no effective workaround is confirmed.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)