CVE-2025-15444 is a critical vulnerability affecting Crypt::Sodium::XS Perl module versions prior to 0.000042, due to its inclusion of a vulnerable libsodium library (versions <= 1.0.20 or released before December 30, 2025). The underlying libsodium flaw, CVE-2025-69277, allows for invalid elliptic curve points in atypical use cases of crypto_core_ed25519_is_valid_point. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or Metasploit modules, the vulnerability has garnered some community discussion, including a SUSE Linux security update mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.000042CPE matchmatch criteria | cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:* | ||
>= 0, < 0.000042CPE match | cpe:2.3:a:iamb:crypt\:\:sodium\:\:xs:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.