Source status: The GnuPG Libgcrypt release announcement directly says the Dilithium context-handling bounds check was reported by Calif.io in collaboration with Claude and Anthropic Research. NVD and distribution trackers corroborate CVE-2026-41990 for the same Libgcrypt Dilithium issue.
Summary
Libgcrypt 1.12.2 fixed a missing bounds check in Dilithium context handling, publicly associated with CVE-2026-41990. The same release also fixed other security bugs, but this entry counts only the Dilithium issue with explicit Claude collaboration attribution.
Attribution
The GnuPG announcement is the primary source. It names Calif.io in collaboration with Claude and Anthropic Research in the release notes for the specific fixed bug.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.