libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
History

Wed, 07 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
References

Tue, 06 Jan 2026 16:45:00 +0000


Fri, 02 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Title libsodium: libsodium: Improper validation of elliptic curve points could lead to data integrity or information disclosure.
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 31 Dec 2025 06:15:00 +0000

Type Values Removed Values Added
Description libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group. libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Wed, 31 Dec 2025 06:00:00 +0000

Type Values Removed Values Added
Description libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptograpbic group.
Weaknesses CWE-184
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-31T05:50:07.422Z

Updated: 2026-01-07T17:06:43.302Z

Reserved: 2025-12-31T05:50:07.155Z

Link: CVE-2025-69277

cve-icon Vulnrichment

Updated: 2026-01-07T17:06:43.302Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-31T06:15:41.513

Modified: 2026-01-07T17:16:02.003

Link: CVE-2025-69277

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-31T05:50:07Z

Links: CVE-2025-69277 - Bugzilla