Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
https://www.openwall.com/lists/oss-security/2026/04/21/1
https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html