Overview
What is CVE-2026-41989?
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
Vulnerability intelligence
CVE-2026-41989 and is rated Medium severity with a CVSS score of 6.7. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.