We received this report on 2026-04-07:
_gcry_ecc_mont_decodepoint() at cipher/ecc-misc.c:441 miscomputes the
destination offset of a zero-padding memset() when decoding an opaque
Curve25519 or X448 point whose byte length is less than half the curve's
coordinate size: [...]
Which affects all Libgcrypt versions >= 1.8.8, GnuPG 2.5 is not affected due to the use of the new KEM API.
Reported-by: Bronson Yen, Calif.io on behalf of Anthropic Coordinated Vulnerability Disclosure program