CVE-2026-57062

LOW

GnuPG < 2.5.20 - Improper Validation of Specified Quantity in Input

Title source: rule
STIX 2.1

Description

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Scores

CVSS v3 2.9
EPSS 0.0014
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (1)
GnuPG/GnuPG < 2.5.20
Published Jun 23, 2026
Tracked Since Jun 23, 2026