CVE-2025-30258LowCVSS 2.7

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

Published
July 11, 2026
Last Modified

🔗 CVE IDs covered (1)