Skip to main content
Version: v1.1.x

CVE-2026-57062

CVE Details

Visit the official vulnerability details page for CVE-2026-57062 to learn more.

Initial Publication

06/23/2026

Last Update

06/25/2026

Third Party Dependency

gnupg2

NIST CVE Summary

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

CVE Severity

2.9

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.6⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.