Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gnupg

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 56
41.8
VTI Score
High

Gnupg is a prominent cryptographic software suite whose core product and supporting libraries—including libgcrypt and libksba—see wide adoption in mail clients, secure communications tools, and command-line encryption workflows, positioning it as a foundational component in the privacy infrastructure landscape. Vulnerabilities affecting the vendor lean toward serious outcomes: a meaningful share reach critical severity and a moderate tendency toward public exploit availability, reflecting the memory-safety and cryptographic-parsing demands of its C-based implementation. The exposure recurs across the primary Gnupg application and its cryptographic libraries through weakness classes including sensitive-information exposure, improper input validation, out-of-bounds writes, and memory-buffer violations, consistent with the parsing complexity inherent to key material and encrypted data handling. Defenders should prioritize patches for this vendor given its role in end-to-end encryption and its presence in mail and messaging infrastructure; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
56
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gnupg over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24881CRITICAL
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT
Jan 27, 20269.836NONO
CVE-2026-24882HIGH
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
Jan 27, 20267.832NONO
CVE-2022-3515CRITICAL
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target syst
Jan 12, 20239.832NONO
CVE-2022-47629CRITICAL
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Dec 20, 20229.832NONO
CVE-2018-12020HIGH
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on
Jun 8, 20187.529NONO
CVE-2008-1530HIGH
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key s
Mar 27, 20089.329NONO
CVE-2026-41989MEDIUM
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Apr 23, 20266.726NONO
CVE-2025-68973HIGH
In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For Extended
Dec 28, 20257.026NONO
CVE-2021-33560HIGH
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window siz
Jun 8, 20217.526NONO
CVE-2019-13050HIGH
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referri
Jun 29, 20197.526NONO
View all 56 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products56 CVEs
11%
46%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (25.0%)
Network26 (46.4%)
Unknown14 (25.0%)
Physical2 (3.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (46.4%)
High16 (28.6%)
Unknown14 (25.0%)
User Interaction
None38 (67.9%)
Unknown14 (25.0%)
Required4 (7.1%)
Privileges Required
Low8 (14.3%)
High0 (0.0%)
None34 (60.7%)
Unknown14 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
5.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gnupg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gnupg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gnupg's Products

View all 4 CNAs →

Top CWEs