libdnf does its own signature verification, but this can be tricked by placing a signature in the main header https://bugzilla.redhat.com/show_bug.cgi?id=1932079 CREATE(Triage):(User=admin) CVE-2021-3445 (https://nvd.nist.gov/vuln/detail/CVE-2021-3445)