Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-68972


In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.


Published

2025-12-27T23:15:40.900

Last Modified

2026-01-09T20:08:47.323

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnupg gnupg ≤ 2.4.8 Yes

References