The speaker disclosed multiple vulnerabilities in GPG, including memory corruption in the PGP message parser, at 39c3 in December 2025. While some bugs were patched, key issues remain unaddressed, with the main developer opting to declare certain features harmful via a blog post instead of fixing code. The talk also presents novel vulnerabilities and demonstrates live the real-world impact of these unresolved footguns.
Background
GnuPG (GPG) is the most widely used PGP implementation for email encryption and digital signatures. The 39c3 conference took place in December 2025 in Berlin.
- Source
- Lobsters
- Published
- Sep 13, 2026 at 01:24 AM
- Score
- 7.0 / 10