Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-24881

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 74.9%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-24881
  • Gnupg » Gnupg » Version: 2.5.13
    cpe:2.3:a:gnupg:gnupg:2.5.13
  • Gnupg » Gnupg » Version: 2.5.14
    cpe:2.3:a:gnupg:gnupg:2.5.14
  • Gnupg » Gnupg » Version: 2.5.15
    cpe:2.3:a:gnupg:gnupg:2.5.15
  • Gnupg » Gnupg » Version: 2.5.16
    cpe:2.3:a:gnupg:gnupg:2.5.16
  • Gpg4win » Gpg4win » Version: Any
    cpe:2.3:a:gpg4win:gpg4win:*


Contact Us

Shodan ® - All rights reserved