JLSEC-2026-496

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-496.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-496.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-496
Upstream
  • CVE-2026-41989
  • EUVD-2026-25192
  • GHSA-wrv8-79m2-qg24
Published
2026-05-14T02:21:35.919Z
Modified
2026-05-14T02:47:55.316585670Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via...
Details

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcrypkdecrypt.

Database specific
{
    "sources": [
        {
            "modified": "2026-04-27T18:33:18.157Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-41989",
            "published": "2026-04-23T05:16:05.750Z",
            "database_specific": {
                "status": "Analyzed"
            },
            "imported": "2026-05-14T00:51:22.580Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41989",
            "id": "CVE-2026-41989"
        },
        {
            "url": "https://api.github.com/advisories/GHSA-wrv8-79m2-qg24",
            "modified": "2026-04-23T06:30:28Z",
            "id": "GHSA-wrv8-79m2-qg24",
            "published": "2026-04-23T06:30:22Z",
            "imported": "2026-05-14T00:51:26.621Z",
            "html_url": "https://github.com/advisories/GHSA-wrv8-79m2-qg24"
        },
        {
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-25192",
            "modified": "2026-04-23T16:22:47Z",
            "id": "EUVD-2026-25192",
            "published": "2026-04-23T04:30:26Z",
            "imported": "2026-05-14T00:51:24.152Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25192"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / Libgcrypt_jll

Package

Name
Libgcrypt_jll
Purl
pkg:julia/Libgcrypt_jll?uuid=d4300ac3-e22c-5743-9152-c294e39db1e4

Affected ranges

Type
SEMVER
Events
Introduced
1.8.11+0
Fixed
1.12.2+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-496.json"