OpenPGP is an open cryptographic standard for encryption and digital signatures rather than a single commercial product, and its vulnerability surface reflects the diverse implementations and integrations across standards-compliant tools and libraries. The sparse observed disclosures center on the protocol and implementation interactions themselves, where complexity in key handling and signature verification can create edge cases; defenders should treat OpenPGP-related advisories as affecting multiple downstream products rather than tracking a unified vendor release cycle. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpgp over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0230MEDIUM TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by | Aug 18, 2004 | 5.0 | 74 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpgp.
Media articles that mention a CVE ID that affects a product developed by Openpgp — matched by CVE ID, not by vendor name.