After gpg.fail: responsible disclosure and GPG's security reckoning
A 39c3 talk details unpatched GPG vulnerabilities, GnuPG's disputed response, and what AI means for security research and disclosure.
A security researcher who discovered multiple vulnerabilities in GNU Privacy Guard (GPG) throughout 2025 presented findings at 39c3, tracing a path from a simple PGP signature spoofing bug to memory corruption in the core message parser affecting nearly all PGP workflows.
Disclosed weeks ahead of the conference, some flaws — including the parser memory corruption — were properly patched. Others were not. Notably, the vulnerability used as the talk's opening demonstration remains unfixed; instead, GnuPG lead developer Werner Koch published a blog post labeling the widely-used feature "harmful," timed to drop on day one of 39c3 without giving the researcher a chance to respond.
The episode highlights recurring tension in open-source security disclosure between researchers and maintainers. The talk also covers newly found minor bugs illustrating the state of the GnuPG codebase, plus broader reflections on AI/LLMs in security research — arguing neither end users nor researchers are doomed by the shift.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work