GHSA-8qff-qr5q-5pr8
HIGHCVE-2025-47934A maliciously modified message can be passed to either openpgp.verify or openpgp.decrypt, causing these functions to return a valid signature verification result while returning data that was not actually signed.
- Affected
- >= 5.0.1, <= 5.11.2, >= 6.0.0-alpha.0, <= 6.1.0
- Fixed in
- 5.11.3
- Weakness
- CWE-347
- Published
- 2025-05-19
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference