Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41989

26
FAUCET Score

CVE-2026-41989 is a heap-based buffer overflow vulnerability in Libgcrypt versions prior to 1.12.2 that can be triggered through specially crafted ECDH ciphertext passed to the gcry_pk_decrypt function, potentially enabling denial of service attacks. The vulnerability has a CVSS v3.1 severity rating of 6.7 (Medium) with a local attack vector requiring high complexity but no user interaction or privileges. The flaw poses a moderate risk with potential for integrity and availability impact, though the extremely low EPSS score of 0.000120000 indicates minimal real-world exploitation probability. There is currently no evidence of active exploitation, and the vulnerability remains inactive on threat intelligence hotlists with no public exploit code readily available. Organizations running affected Libgcrypt versions should prioritize patching to version 1.12.2 or later as part of routine security maintenance, though the immediate threat level is low.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.8.8, < 1.10.4CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
>= 1.11.0, < 1.11.3CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*
>= 1.12.0, < 1.12.2CPE matchmatch criteria
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 5th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: azl3 libgcrypt 1.10.3-1 on Azure Linux 3.0Fixed in: 1.10.3-2
microsoftpatch availablevia msrc
Product: azl3 libgcrypt 1.10.3-2 on Azure Linux 3.0Fixed in: 1.10.3-2
microsoftpatch availablevia msrc
Product: 21235-17084Fixed in: 1.10.3-2
microsoftpatch availablevia msrc
Product: 21310-17084Fixed in: 1.10.3-2
ubuntupatch availablevia ubuntu_usn
Product: libgcrypt20 (questing)Fixed in: 1.11.0-7ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: libgcrypt20 (resolute)Fixed in: 1.12.0-2ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: libgcrypt20 (jammy)Fixed in: 1.9.4-3ubuntu3.2
ubuntupatch availablevia ubuntu_usn
Product: libgcrypt20 (noble)Fixed in: 1.10.3-2ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8319-1

Libgcrypt vulnerabilities

May 27, 2026
microsoft2026-Apr/CVE-2026-41989Low

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

Apr 14, 2026

References

cert-portal.siemens.com / productcert/html/ssa-019113.html
cert-portal.siemens.com / productcert/html/ssa-082556.html
dev.gnupg.org / T8211
Broken Link
lists.gnupg.org / pipermail/gnupg-announce/2026q2/000503.html
Third Party Advisory
openwall.com / lists/oss-security/2026/04/21/1
Third Party Advisory