Skip to main content

CVE-2026-24883

CVE Details

Visit the official vulnerability details page for CVE-2026-24883 to learn more.

Initial Publication

01/27/2026

Last Update

02/06/2026

Third Party Dependency

gnupg2

NIST CVE Summary

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).

CVE Severity

3.7

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.