Iamb develops the Crypt cryptographic library, a focused product with prominence in the software supply chain despite its narrow scope, where its durable signal centers on cryptographic-verification and integer-arithmetic concerns. The observed weakness classes—improper verification of cryptographic signatures and integer overflow—reflect the low-level mathematical operations inherent to cryptographic implementations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iamb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15444CRITICAL Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
libsodium <= 1.0.20 or a version of libsodium released before December 30, | Jan 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30910HIGH Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows.
Combined aead encryption, combined signature creation, and bin2hex functions do not check tha | Mar 8, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iamb.
Media articles that mention a CVE ID that affects a product developed by Iamb — matched by CVE ID, not by vendor name.