CVE-2026-41989

· NIST NVD ↗

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

MEDIUM
CVSS severity
6.7
CVSS base score
2026-04-23
Published

CWE codes

CWE-787

Affected products

gnupg:libgcrypt

Sources