A security researcher disclosed multiple vulnerabilities in GPG discovered in 2025, including signature spoofing and memory corruption bugs. While some issues were patched, others remained unaddressed despite advance notice, prompting a detailed talk at 39c3 examining the vulnerabilities, GnuPG's response, and broader implications for responsible disclosure and security.