CVE-2025-30258: Gnupg

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

Affected products

  • Gnupg Gnupg: before 2.4.8 (fixed in 2.4.8); from 2.5.0, before 2.5.5 (fixed in 2.5.5)

Published 2025-03-19. Last modified 2026-06-17.