{
  "id": 6965445,
  "title": "The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 [32:37]",
  "url": "https://urgent.news/2026/09/12/the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-12T17:24:59.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://media.ccc.de/v/2026-728-the-gpg-fail-aftermath-on-responsible-disclosure-gpg-and-the-state-of-security-in-2026"
  },
  "original_language": "en",
  "account": "In 2025, the speaker discovered and disclosed multiple vulnerabilities in GPG, the most widely used PGP implementation. Some of these bugs were later fixed. The speaker held a talk at 39c3 to describe the experience and aftermath of finding these vulnerabilities, showcasing novel ones and discussing the current state of security in 2026. At the time, the speaker had a positive view of PGP and the GNU Privacy Guard, but their perspective changed after uncovering a vulnerability that allowed easy spoofing of PGP signatures when naively opened with GPG. This vulnerability eventually evolved into several independent ones, including a memory corruption issue in the basic PGP message parser that affected nearly all PGP-related workflows. The speaker disclosed these vulnerabilities a few weeks before 39c3 in December 2025.\n\nWhile some of the vulnerabilities, such as the memory corruption bug, were addressed properly, others were not. For instance, one of the initial vulnerabilities used for the introduction hook in the 39c3 talk remains unpatched. Instead of promptly fixing the code, the main developer of GnuPG, Werner Koch, published a blog post in December 2025 declaring the widely-used feature harmful, which was shared on the first day of 39c3, leaving no time for a response from the speaker and others. Several disgruntled comments followed, but many of the flaws still remain unaddressed.\n\nIn the talk, the speaker demonstrated the real impact of the footguns (unaddressed issues) in GPG, without using any zero-day vulnerabilities. They showed how severe the problem of these unpatched flaws truly is. Additionally, the speaker presented several novel vulnerabilities in GPG, which while not as impactful as the previous examples, are still significant bugs that should not have been present in the production code. The talk concluded with general commentary on the state of security and responsible disclosure, as well as the role of AI/LLMs in security, using the gpg.fail vulnerabilities as examples. The speaker emphasized that while end users and security researchers are not doomed, both groups need to take the situation seriously.",
  "summary": "In 2025, I [the speaker] found and disclosed a bunch of vulnerabilities in GPG, the most used PGP implementation, and held a talk at 39c3 about it. Some of the bugs ended up getting fixed. This talk describes the adventure and aftermath of getting there, shows some novel ones, and talks about the state of security in 2026. May contain zero-days =) Until May 2025, I liked PGP, and the GNU Privacy…",
  "key_points": [
    "Speaker discovered and disclosed multiple GPG vulnerabilities in 2025",
    "Unpatched vulnerability allowed easy spoofing of PGP signatures",
    "Speaker emphasized need for serious security and responsible disclosure"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}