The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4021.json"