Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69277

Опубликовано: 31 дек. 2025
Источник: nvd
CVSS3: 4.5
EPSS Низкий

Описание

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

EPSS

Процентиль: 1%
0.00007
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-184

Связанные уязвимости

CVSS3: 4.5
ubuntu
3 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
redhat
3 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
msrc
3 месяца назад

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

CVSS3: 4.5
debian
3 месяца назад

libsodium before ad3004e, in atypical use cases involving certain cust ...

CVSS3: 4.5
github
3 месяца назад

libsodium has Incomplete List of Disallowed Inputs

EPSS

Процентиль: 1%
0.00007
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-184