Products: 4
    Vulnerabilities: 56
    Known Exploited: 0
    3
    Critical Level Threats
    21
    High Level Threats
    24
    Medium Level Threats
    8
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-57062

    CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

    Last Modified: Jun 24, 2026
    Published: Jun 23, 2026

    CVE-2026-41990

    Libgcrypt: Libgcrypt: Denial of Service or data integrity issues from missing bounds check during Dilithium signing.

    Last Modified: Apr 28, 2026
    Published: Apr 23, 2026

    CVE-2026-41989

    Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

    Last Modified: Apr 24, 2026
    Published: Apr 23, 2026

    CVE-2026-24883

    GnuPG: GnuPG: Denial of service due to specially crafted signature packet

    Last Modified: Apr 18, 2026
    Published: Jan 27, 2026

    CVE-2026-24882

    GnuPG: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

    Last Modified: Apr 18, 2026
    Published: Jan 27, 2026
    Items Per Page
    Gnupg Vulnerabilities & Security CVEs | CVE-DB