Gnu privacy guard (gnupg)
This hub aggregates every CVE we track for Gnu privacy guard (gnupg), a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Security Productssecurity product
3
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2LOW1
Monthly trend
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Gnu privacy guard (gnupg).
- CVE-2025-30258In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify ...2.7
- CVE-2019-14855A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This i...7.5
- CVE-2019-13050Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on t...7.5
Product normalization is registry-driven with AI assist and human review. How it works