Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4435-1 | libsodium security update |
Debian DSA |
DSA-6094-1 | libsodium security update |
Github GHSA |
GHSA-mrfv-m5wm-5w6w | libsodium has Incomplete List of Disallowed Inputs |
Ubuntu USN |
USN-7949-1 | Sodium vulnerability |
Wed, 07 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 06 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libsodium: libsodium: Improper validation of elliptic curve points could lead to data integrity or information disclosure. | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 31 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group. | libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. |
Wed, 31 Dec 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group. | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-07T17:06:43.302Z
Reserved: 2025-12-31T05:50:07.155Z
Link: CVE-2025-69277
Updated: 2026-01-07T17:06:43.302Z
Status : Deferred
Published: 2025-12-31T06:15:41.513
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-69277
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN