Skip to main content

Vendor archive

gnupg CVEs

Beta · best-effort

55 CVEs tagged to vendor gnupg3 Critical, 21 High, 24 Medium, 7 Low, 0 Unrated.

CVE-2026-41990

Published Apr 23, 2026

Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-41989

Published Apr 23, 2026

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

CVSS 6.7 · Medium
evidence mentions
7
Buzz score
40.8
Vendor/product tagsBeta · best-effort

CVE-2026-24883

Published Jan 27, 2026

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application c…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-24882

Published Jan 27, 2026

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

CVSS 8.4 · High
evidence mentions
7
Buzz score
35.3
Vendor/product tagsBeta · best-effort

CVE-2026-24881

Published Jan 27, 2026

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYP…

CVSS 8.1 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2025-68973

Published Dec 28, 2025

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For Extende…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68972

Published Dec 27, 2025

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed mater…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30258

Published Mar 19, 2025

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3219

Published Feb 23, 2023

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-40528

Published Sep 6, 2021

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25125

Published Sep 3, 2020

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1607

Published Nov 20, 2019

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a deni…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1606

Published Nov 20, 2019

The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12904

Published Jun 20, 2019

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C impleme…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000858

Published Dec 20, 2018

GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 55 CVEsPage 1 of 3