CVE-2026-24881 | GnuPG up to 2.5.16 CMS EnvelopedData Message stack-based overflow (Nessus ID 297012 / WID-SEC-2026-0231)
A vulnerability classified as critical was found in GnuPG up to 2.5.16. This affects an unknown part of the component CMS EnvelopedData Message Handler. Such manipulation leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-24881. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.