CVE-2025-30258: Gnupg
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."
Affected products
- Gnupg Gnupg: before 2.4.8 (fixed in 2.4.8); from 2.5.0, before 2.5.5 (fixed in 2.5.5)
Published 2025-03-19. Last modified 2026-06-17.