{"id":"CVE-2025-69277","aliases":["GHSA-mrfv-m5wm-5w6w","PYSEC-2026-1448","PYSEC-2026-3002"],"url":"https://o3.security/vulnerability/CVE-2025-69277","summary":"libsodium has Incomplete List of Disallowed Inputs","details":"libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.","published":"2025-12-31T05:50:07.422Z","modified":"2026-08-12T15:14:57.756502Z","cvss":{"score":4.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"paragonie/sodium_compat","fixedVersion":"2.5.0"},{"ecosystem":"Packagist","name":"paragonie/sodium_compat","fixedVersion":"1.24.0"},{"ecosystem":"PyPI","name":"pynacl","fixedVersion":"1.6.2"},{"ecosystem":"PyPI","name":"hdwallet","fixedVersion":"3.6.1"}],"fix":{"url":"https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae","label":"jedisct1/libsodium@ad3004e"},"references":[{"type":"WEB","url":"https://00f.net/2025/12/30/libsodium-vulnerability/"},{"type":"WEB","url":"https://ianix.com/pub/ed25519-deployment.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00004.html"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=46435614"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69277.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69277"},{"type":"REPORT","url":"https://github.com/pyca/pynacl/issues/920"},{"type":"FIX","url":"https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae"},{"type":"FIX","url":"https://github.com/pyca/pynacl/commit/96314884d88d1089ff5f336dba61d7abbcddbbf7"},{"type":"FIX","url":"https://github.com/pyca/pynacl/commit/ecf41f55a3d8f1e10ce89c61c4b4d67f3f4467cf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:14:57.756502Z"}}