
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41989 is a heap-based buffer overflow vulnerability in Libgcrypt's ECDH decryption function (gcry_pk_decrypt) that can be triggered via crafted ECDH ciphertext, potentially leading to denial of service or heap corruption. It affects Libgcrypt versions 1.8.8 through 1.10.3, 1.11.0 through 1.11.2, and 1.12.0 through 1.12.1. The vulnerability was publicly disclosed on April 21, 2026, via the oss-security mailing list, with patched releases announced the same day by Werner Koch of the GnuPG project. It carries a CVSS v3.1 base score of 6.7 (Medium) (Github Advisory, oss-security).
The root cause is an out-of-bounds write (CWE-787) — specifically, a possible buffer overwrite with zeroes during ECDH decryption processing in gcry_pk_decrypt. The flaw is triggered when the library processes specially crafted ECDH ciphertext using NIST, Brainpool, X448, or X25519 curves, causing data to be written beyond the allocated heap buffer boundaries. Exploitation requires local access and high attack complexity, as the attacker must be able to supply malicious ciphertext to the vulnerable decryption function. GnuPG versions since 2.5.7 are not affected because they use a different encryption API (oss-security, Github Advisory).
Successful exploitation can cause denial of service by crashing the application processing the crafted ECDH ciphertext, and may result in heap corruption that could potentially enable code execution or data manipulation. The integrity and availability impacts are rated High, while confidentiality is unaffected per the CVSS scoring. The vulnerability's local attack vector limits its reach, but any application or service relying on Libgcrypt for ECDH decryption — including cryptographic tools and secure communication software — is at risk (Github Advisory, oss-security).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The high attack complexity and local access requirement further reduce practical exploitability (Github Advisory).
The GnuPG project has released patched versions addressing this vulnerability: Libgcrypt 1.12.2, 1.11.3, and 1.10.4. Version 1.12.2 is the recommended upgrade as it is fully compatible with all earlier versions. Organizations should prioritize upgrading all systems running affected versions (1.8.8–1.10.3, 1.11.0–1.11.2, or 1.12.0–1.12.1). As an interim measure, limiting local access to systems running vulnerable Libgcrypt versions can reduce exposure. Source tarballs are available from the GnuPG FTP server and mirrors (oss-security, Github Advisory).
The vulnerability was disclosed by Werner Koch of the GnuPG/g10 Code GmbH team via the gnupg-announce and oss-security mailing lists, with coordinated patched releases on April 21, 2026. The Yocto Project security list, Ubuntu (USN-8319-1), Amazon Linux (ALAS2023-2026-1705), Fedora, and Debian have all issued downstream advisories or updates. Tenable published multiple Nessus detection plugins (IDs 309928, 311104, 315026, 316550) shortly after disclosure, and the vulnerability was tracked by ENISA's EUVD database (oss-security, Ubuntu Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
libgcrypt20: 1.10.1-3+deb12u1
sid
libgcrypt20: 1.12.2-1
trixie
libgcrypt20: 1.11.0-7+deb13u1
bionic (esm-infra)
libgcrypt20
bionic (fips-updates)
libgcrypt20
bionic (fips)
libgcrypt20
devel
libgcrypt20
focal (esm-infra)
libgcrypt20
focal (fips-updates)
libgcrypt20
focal (fips)
libgcrypt20
jammy
libgcrypt20: 1.9.4-3ubuntu3.2
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."