PatchSiren

gnupg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM gnupg CVE published 2026-07-14

CVE-2026-41989

A medium-severity vulnerability, CVE-2026-41989, was found in Libgcrypt, a cryptographic library. The vulnerability allows for a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. The CVE record was published on 2026-04-23T05:16:05.750Z and has not been modified since then. This vulnerability has a CVSS score of 6.7 and a severity of MEDIUM. Users of affected [truncated]

HIGH GnuPG CVE published 2026-01-27

CVE-2026-24881

CVE-2026-24881 is a high-severity vulnerability in GnuPG, a popular open-source encryption software. The vulnerability can cause a stack-based buffer overflow, potentially leading to denial of service and remote code execution. GnuPG versions prior to 2.5.17 are affected. The vulnerability was publicly disclosed on January 27, 2026, and has been actively monitored since then. Users and organizations using [truncated]