Gnupg is a prominent cryptographic software suite whose core product and supporting libraries—including libgcrypt and libksba—see wide adoption in mail clients, secure communications tools, and command-line encryption workflows, positioning it as a foundational component in the privacy infrastructure landscape. Vulnerabilities affecting the vendor lean toward serious outcomes: a meaningful share reach critical severity and a moderate tendency toward public exploit availability, reflecting the memory-safety and cryptographic-parsing demands of its C-based implementation. The exposure recurs across the primary Gnupg application and its cryptographic libraries through weakness classes including sensitive-information exposure, improper input validation, out-of-bounds writes, and memory-buffer violations, consistent with the parsing complexity inherent to key material and encrypted data handling. Defenders should prioritize patches for this vendor given its role in end-to-end encryption and its presence in mail and messaging infrastructure; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnupg over time
Signals from CVEs in this vendor scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24881CRITICAL In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT | Jan 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-24882HIGH In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys. | Jan 27, 2026 | 7.8 | 32 | NO | NO |
CVE-2022-3515CRITICAL A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target syst | Jan 12, 2023 | 9.8 | 32 | NO | NO |
CVE-2022-47629CRITICAL Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. | Dec 20, 2022 | 9.8 | 32 | NO | NO |
CVE-2018-12020HIGH mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on | Jun 8, 2018 | 7.5 | 29 | NO | NO |
CVE-2008-1530HIGH GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key s | Mar 27, 2008 | 9.3 | 29 | NO | NO |
CVE-2026-41989MEDIUM Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt. | Apr 23, 2026 | 6.7 | 26 | NO | NO |
CVE-2025-68973HIGH In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For Extended | Dec 28, 2025 | 7.0 | 26 | NO | NO |
CVE-2021-33560HIGH Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window siz | Jun 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2019-13050HIGH Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referri | Jun 29, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (56 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnupg.
Media articles that mention a CVE ID that affects a product developed by Gnupg — matched by CVE ID, not by vendor name.