CVE Explorer
CVE-2025-69277
libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"libsodium","vendor":"libsodium","versions":[{"lessThan":"ad3004ec8731730e93fcfbbc824e67eadc1c1bae","status":"affected","version":"0","versionType":"git"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-184","description":"CWE-184 Incomplete List of Disallowed Inputs","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"url":"https://00f.net/2025/12/30/libsodium-vulnerability/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/1
{"url":"https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/0
{"url":"https://github.com/pyca/pynacl/commit/96314884d88d1089ff5f336dba61d7abbcddbbf7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/6
{"url":"https://github.com/pyca/pynacl/commit/ecf41f55a3d8f1e10ce89c61c4b4d67f3f4467cf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/5
{"url":"https://github.com/pyca/pynacl/issues/920"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/4
{"url":"https://ianix.com/pub/ed25519-deployment.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/3
{"url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00004.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/adp/1/references/0
{"url":"https://news.ycombinator.com/item?id=46435614"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b3f1ade0c3070731af8cb6d1d0a45a21f9d543a762608fd6c67a35779610771b · sha256:16a98c03d3918f94… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.