CVE-2026-41989: Gnupg Libgcrypt
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Affected products
- Gnupg Libgcrypt: from 1.8.8, before 1.10.4 (fixed in 1.10.4); from 1.11.0, before 1.11.3 (fixed in 1.11.3); from 1.12.0, before 1.12.2 (fixed in 1.12.2)
Published 2026-04-23. Last modified 2026-07-14.