Skip to main content

CVE-2026-24881

CVE Details

Visit the official vulnerability details page for CVE-2026-24881 to learn more.

Initial Publication

01/27/2026

Last Update

01/29/2026

Third Party Dependency

gnupg2

NIST CVE Summary

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

CVE Severity

8.1

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Undergoing Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.