CVE-2025-15444

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:*

History

10 Mar 2026, 17:00

Type Values Removed Values Added
CWE CWE-347
First Time Iamb
Iamb crypt\
References () https://00f.net/2025/12/30/libsodium-vulnerability/ - () https://00f.net/2025/12/30/libsodium-vulnerability/ - Third Party Advisory
References () https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae - () https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae - Patch
References () https://metacpan.org/dist/Crypt-Sodium-XS/changes - () https://metacpan.org/dist/Crypt-Sodium-XS/changes - Product, Release Notes
CPE cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:*

06 Jan 2026, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Jan 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 01:16

Updated : 2026-03-10 17:00


NVD link : CVE-2025-15444

Mitre link : CVE-2025-15444

CVE.ORG link : CVE-2025-15444


JSON object : View

Products Affected

iamb

  • crypt\
CWE
CWE-347

Improper Verification of Cryptographic Signature