CVE-2025-15444

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:*

History

No history.

Information

Published : 2026-01-06 01:16

Updated : 2026-03-10 17:00


NVD link : CVE-2025-15444

Mitre link : CVE-2025-15444

CVE.ORG link : CVE-2025-15444


JSON object : View

Products Affected

iamb

  • crypt\
CWE
CWE-347

Improper Verification of Cryptographic Signature