VDB

JLSEC-2026-123

JLSEC-2026-123 PUBLISHED CVSS 5 MEDIUM

Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against `mpi_powm`, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

Risk Scores

CVSS 2.0
5

Affected Products

VendorProductVersions
JuliaLibgcrypt_jll0, 0
JuliaLibgcrypt_jll0

Timeline

  • Apr 17, 2026 CVE Published
  • Jul 25, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›