All findings

CVE-2026-41990 medium

Libgcrypt credits Claude-assisted Calif.io report for Dilithium bounds check

The GnuPG Libgcrypt 1.12.2 security release credits Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-41990, a missing bounds check in Dilithium context handling.

Bug class
Post-quantum signature context bounds check
Affected codebase
Libgcrypt
Credited system
Claude / Anthropic Research
Disclosed
April 21, 2026
Attribution
Direct source attribution
Severity
medium
Source status: The GnuPG Libgcrypt release announcement directly says the Dilithium context-handling bounds check was reported by Calif.io in collaboration with Claude and Anthropic Research. NVD and distribution trackers corroborate CVE-2026-41990 for the same Libgcrypt Dilithium issue.

Summary

Libgcrypt 1.12.2 fixed a missing bounds check in Dilithium context handling, publicly associated with CVE-2026-41990. The same release also fixed other security bugs, but this entry counts only the Dilithium issue with explicit Claude collaboration attribution.

Attribution

The GnuPG announcement is the primary source. It names Calif.io in collaboration with Claude and Anthropic Research in the release notes for the specific fixed bug.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.