Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-24883

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 37.7%
CVSS Severity
CVSS v3 Score 3.7
Products affected by CVE-2026-24883
  • Gnupg » Gnupg » Version: 2.5.13
    cpe:2.3:a:gnupg:gnupg:2.5.13
  • Gnupg » Gnupg » Version: 2.5.14
    cpe:2.3:a:gnupg:gnupg:2.5.14
  • Gnupg » Gnupg » Version: 2.5.15
    cpe:2.3:a:gnupg:gnupg:2.5.15
  • Gnupg » Gnupg » Version: 2.5.16
    cpe:2.3:a:gnupg:gnupg:2.5.16
  • Gpg4win » Gpg4win » Version: Any
    cpe:2.3:a:gpg4win:gpg4win:*


Contact Us

Shodan ® - All rights reserved