Libgcrypt

Vendor:

First CVE: Aug 19, 2013 · Active for 12 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libgcrypt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2013
12 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

CVE Severity & Scoring

Libgcrypt17 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local4 (23.5%)
Network9 (52.9%)
Unknown2 (11.8%)
Physical2 (11.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (29.4%)
High10 (58.8%)
Unknown2 (11.8%)
User Interaction
None15 (88.2%)
Unknown2 (11.8%)
Required0 (0.0%)
Privileges Required
Low2 (11.8%)
High0 (0.0%)
None13 (76.5%)
Unknown2 (11.8%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Apr 23, 20266.726NONO
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window siz
Jun 8, 20217.526NONO
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended
Jan 29, 20217.825NONO
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the slidi
Jul 26, 20186.825NONO
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by readin
Feb 7, 20187.524NONO
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of t
Sep 6, 20215.922NONO
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.
Aug 29, 20177.522NONO
In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.
Jun 11, 20175.922NONO
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implemen
Jun 20, 20195.921NONO
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to ob
Dec 13, 20165.321NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Libgcrypt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.017.81.1%00
1.8.415.92.1%00
1.7.215.33.6%00
1.7.115.33.6%00
1.7.015.33.6%00
1.6.515.33.6%00
1.6.415.33.6%00
1.6.315.33.6%00
1.6.215.33.6%00
1.6.115.33.6%00
1.6.015.33.6%00
1.5.212.10.5%00
1.5.122.00.5%00
1.5.022.00.5%00
1.4.622.00.5%00
1.4.522.00.5%00
1.4.422.00.5%00
1.4.322.00.5%00
1.4.022.00.5%00