CVE-2026-41989 is a heap-based buffer overflow vulnerability in Libgcrypt versions prior to 1.12.2 that can be triggered through specially crafted ECDH ciphertext passed to the gcry_pk_decrypt function, potentially enabling denial of service attacks. The vulnerability has a CVSS v3.1 severity rating of 6.7 (Medium) with a local attack vector requiring high complexity but no user interaction or privileges. The flaw poses a moderate risk with potential for integrity and availability impact, though the extremely low EPSS score of 0.000120000 indicates minimal real-world exploitation probability. There is currently no evidence of active exploitation, and the vulnerability remains inactive on threat intelligence hotlists with no public exploit code readily available. Organizations running affected Libgcrypt versions should prioritize patching to version 1.12.2 or later as part of routine security maintenance, though the immediate threat level is low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.8.8, < 1.10.4CPE matchmatch criteria | cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.3CPE matchmatch criteria | cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* | ||
>= 1.12.0, < 1.12.2CPE matchmatch criteria | cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.