Known Vulnerabilities for Openpgp by Pgp
Listed below are 1 of the newest known vulnerabilities associated with "Openpgp" by "Pgp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103647 json | Cross-site scripting in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote attacker who can sen... | Not Provided | 2026-10-08 | 2026-10-08 |
| CVE-2026-85515 json | In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the ... | Not Provided | 2026-10-03 | 2026-10-05 |
| CVE-2026-71887 json | In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Su... | Not Provided | 2026-10-03 | 2026-10-05 |
| CVE-2026-71886 json | In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust d... | Not Provided | 2026-10-03 | 2026-10-05 |
| CVE-2026-63574 json | Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacket... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-59649 json | In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue als... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-59648 json | In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects ... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-59643 json | In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bou... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-59640 json | In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also ... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-42784 json | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpack... | Not Provided | 2026-09-16 | 2026-10-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pgp | Openpgp | - |