CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It may be remotely exploitable.
CVE
CVE-2025-67897
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%
Original NVD Description
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.