libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 31 Dec 2025 06:15:00 +0000

Type Values Removed Values Added
Description libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group. libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Wed, 31 Dec 2025 06:00:00 +0000

Type Values Removed Values Added
Description libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group.
Weaknesses CWE-184
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-31T06:03:26.026Z

Reserved: 2025-12-31T05:50:07.155Z

Link: CVE-2025-69277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-31T06:15:41.513

Modified: 2025-12-31T06:15:41.513

Link: CVE-2025-69277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses