libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 https://www.cve.org/CVERecord?id=CVE-2025-69277 .
The libsodium vulnerability states:
In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.
No analysis available yet.
Vendor Solution
Upgrade to version 0.000042 or later
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iamb
Iamb crypt\ |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Iamb
Iamb crypt\ |
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perl
Perl crypt::sodium::xs |
|
| Vendors & Products |
Perl
Perl crypt::sodium::xs |
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 06 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 06 Jan 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability. | |
| Title | Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium | |
| Weaknesses | CWE-1395 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-01-06T19:01:27.678Z
Reserved: 2026-01-03T22:06:02.639Z
Link: CVE-2025-15444
Updated: 2026-01-06T14:23:58.300Z
Status : Analyzed
Published: 2026-01-06T01:16:01.240
Modified: 2026-03-10T17:00:25.563
Link: CVE-2025-15444
OpenCVE Enrichment
Updated: 2026-01-08T09:50:06Z