CVE-2025-40914 describes an integer overflow vulnerability within the Perl CryptX library, specifically affecting versions prior to 0.087, due to an embedded susceptible version of libtommath. This critical vulnerability, rated 9.8 CVSS, allows for unauthenticated remote exploitation with high impact on confidentiality, integrity, and availability, requiring low attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MIK | CryptX | >= 0.002, <= 0.086CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CryptX vulnerabilities
Mar 26, 2026USN-8128-1: CryptX vulnerabilities
Mar 26, 2026USN-8128-1: CryptX vulnerabilities
Mar 26, 2026Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow
Jun 10, 2025