GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2022-34903.json"