Skip to content
Critical CVE-2026-42784 Vulnerability in sequoia-openpgp

Critical CVE-2026-42784 Vulnerability in sequoia-openpgp

First seen 17 Sep 2026, 01:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 03:51 UTC
  • CVE-2026-42784 allows signature forgery via key flag confusion.
  • Red Hat products using sequoia-openpgp are at risk of cryptographic integrity compromise.
  • No effective workaround is available; urgent remediation is required.

A critical vulnerability (CVE-2026-42784) was discovered in the sequoia-openpgp library, affecting its ability to correctly infer key flags for older certificates. This flaw allows attackers to bypass back-signature checks, enabling them to bind arbitrary subkeys to their own certificates and forge signatures. The potential impact includes a complete compromise of cryptographic integrity, affecting Red Hat products using sequoia-openpgp. Exploitation could lead to unauthorized actions, data manipulation, and undermined trust in automated systems. Mitigation options are currently limited, and organizations relying on automated build and deployment pipelines are particularly at risk. The CVE was published on September 16, 2026, and no effective workaround has been confirmed. Immediate action is advised for those affected.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-42784 published
A critical vulnerability in sequoia-openpgp was disclosed, allowing attackers to forge signatures.
access.redhat.com
2026-09-17
Vulnerability reported
Both Red Hat and Red Packet Security reported on the critical vulnerability, emphasizing its impact on cryptographic integrity.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-42784 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed