Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-24882

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 33.7%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2026-24882
  • Gnupg » Gnupg » Version: 2.5.13
    cpe:2.3:a:gnupg:gnupg:2.5.13
  • Gnupg » Gnupg » Version: 2.5.14
    cpe:2.3:a:gnupg:gnupg:2.5.14
  • Gnupg » Gnupg » Version: 2.5.15
    cpe:2.3:a:gnupg:gnupg:2.5.15
  • Gnupg » Gnupg » Version: 2.5.16
    cpe:2.3:a:gnupg:gnupg:2.5.16
  • Gpg4win » Gpg4win » Version: Any
    cpe:2.3:a:gpg4win:gpg4win:*


Contact Us

Shodan ® - All rights reserved