CVE-2026-24881: Gnupg

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

Affected products

  • Gnupg Gnupg: from 2.5.13, before 2.5.17 (fixed in 2.5.17)
  • GPG4WIN GPG4WIN: from 5.0.0, before 5.0.1 (fixed in 5.0.1)

Published 2026-01-27. Last modified 2026-07-15.