Sodiumoxide is a Rust-language binding to the widely used libsodium cryptographic library, providing a focused product footprint centered on the sodiumoxide crate itself. The vendor's disclosure record reflects the foundational nature of cryptographic software, where the available information on reported weaknesses remains limited in specificity. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sodiumoxide Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25002CRITICAL An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties. | Dec 31, 2020 | 9.8 | 30 | NO | NO |
CVE-2017-1000168MEDIUM sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys | Nov 17, 2017 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sodiumoxide Project.
Media articles that mention a CVE ID that affects a product developed by Sodiumoxide Project — matched by CVE ID, not by vendor name.