{"id":"PYSEC-2026-3002","summary":"libsodium has Incomplete List of Disallowed Inputs","details":"libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.\n\nThis advisoory lists packages in the GitHub Advisory Database's [supported ecosystems](https://github.com/github/advisory-database?tab=readme-ov-file#supported-ecosystems) that are affected by this vulnerability due to a vulnerable dependency.","aliases":["CVE-2025-69277","GHSA-mrfv-m5wm-5w6w","PYSEC-2026-1448"],"modified":"2026-07-13T16:56:18.387392943Z","published":"2026-07-13T14:36:34.230612Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69277"},{"type":"WEB","url":"https://github.com/pyca/pynacl/issues/920"},{"type":"WEB","url":"https://github.com/hdwallet-io/python-hdwallet/pull/124"},{"type":"WEB","url":"https://github.com/jedisct1/libsodium/commit/ad3004ec8731730e93fcfbbc824e67eadc1c1bae"},{"type":"WEB","url":"https://github.com/paragonie/sodium_compat/commit/2cb48f26130919f92f30650bdcc30e6f4ebe45ac"},{"type":"WEB","url":"https://github.com/paragonie/sodium_compat/commit/4714da6efdc782c06690bc72ce34fae7941c2d9f"},{"type":"WEB","url":"https://github.com/pyca/pynacl/commit/96314884d88d1089ff5f336dba61d7abbcddbbf7"},{"type":"WEB","url":"https://github.com/pyca/pynacl/commit/ecf41f55a3d8f1e10ce89c61c4b4d67f3f4467cf"},{"type":"WEB","url":"https://00f.net/2025/12/30/libsodium-vulnerability"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/paragonie/sodium_compat/2025-12-30.yaml"},{"type":"PACKAGE","url":"https://github.com/paragonie/sodium_compat"},{"type":"WEB","url":"https://ianix.com/pub/ed25519-deployment.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00004.html"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=46435614"},{"type":"PACKAGE","url":"https://pypi.org/project/pynacl"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mrfv-m5wm-5w6w"}],"affected":[{"package":{"name":"pynacl","ecosystem":"PyPI","purl":"pkg:pypi/pynacl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.2"}]}],"versions":["0.1.0","0.2.0","0.2.1","0.2.2","0.2.3","0.3.0","1.0","1.0.1","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.3.0","1.4.0","1.5.0","1.6.0","1.6.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pynacl/PYSEC-2026-3002.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}