Gnupg
5 known vulnerabilities
Top Products
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause
Frequently Asked Questions
How many CVEs affect Gnupg?
Gnupg has 5 CVE records in our database, including 0 critical and 2 high severity vulnerabilities.
What are the most severe Gnupg vulnerabilities?
Gnupg has 0 critical severity (CVSS 9.0+) and 2 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Gnupg vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gnupg products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gnupg Vulnerabilities
CyberStrike scans your infrastructure for Gnupg vulnerabilities and provides real-time remediation guidance.
Get Started