CVE-2025-15444: Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
Published Jan 6, 2026
·Updated
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
Affected Software
6 affected componentsFixes available
cpan/Crypt-Sodium-XS<0.000042
libsodium<=1.0.20, >undefined
Microsoft cbl2 libsodium 1.0.18-6
Microsoft azl3 libsodium 1.0.19-2
Microsoft azl3 libsodium 1.0.19-1
Iamb Crypt\<0.000042
Remediation
Information
Upgrade to version 0.000042 or later
Event History
Jan 6, 2026
CVE Published
via MITRE·12:22 AM
Data Sourced
via MITRE·12:22 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 9, 2026
Data Sourced
via Microsoft·09:10 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·09:10 AM
Affected Software
Updated
via Microsoft·09:10 AM
Affected Software
Updated
via Microsoft·09:10 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-15444?
CVE-2025-15444 is classified as a moderate severity vulnerability due to its potential impact on cryptographic operations.
2
How do I fix CVE-2025-15444?
To fix CVE-2025-15444, update to Crypt::Sodium::XS version 0.000042 or higher and ensure libsodium is updated to a version released after December 30, 2025.
3
What versions of libsodium are affected by CVE-2025-15444?
CVE-2025-15444 affects libsodium versions up to and including 1.0.20 and any version released before December 30, 2025.
4
Which software is affected by CVE-2025-15444?
Crypt::Sodium::XS module versions prior to 0.000042 and libsodium versions up to 1.0.20 are affected by CVE-2025-15444.
5
What are the potential consequences of CVE-2025-15444?
Exploitation of CVE-2025-15444 could lead to compromised cryptographic security, impacting data confidentiality and integrity.