Description
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium

libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 .

The libsodium vulnerability states:

In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.
Published: 2026-01-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to version 0.000042 or later

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Iamb
Iamb crypt\
Weaknesses CWE-347
CPEs cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:*
Vendors & Products Iamb
Iamb crypt\

Thu, 08 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Perl
Perl crypt::sodium::xs
Vendors & Products Perl
Perl crypt::sodium::xs

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 06 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Moderate


Tue, 06 Jan 2026 00:30:00 +0000

Type Values Removed Values Added
Description Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.
Title Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
Weaknesses CWE-1395
References

Subscriptions

Iamb Crypt\
Perl Crypt::sodium::xs
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-01-06T19:01:27.678Z

Reserved: 2026-01-03T22:06:02.639Z

Link: CVE-2025-15444

cve-icon Vulnrichment

Updated: 2026-01-06T14:23:58.300Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-06T01:16:01.240

Modified: 2026-03-10T17:00:25.563

Link: CVE-2025-15444

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-06T00:22:50Z

Links: CVE-2025-15444 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-08T09:50:06Z

Weaknesses