CVE-2026-30909Disclosure(timlegge / crypt\)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing an undersized output buffer. Encountering this issue is unlikely as the message length would need to be very large. For bin2hex() the bin_len would have to be > SIZE_MAX / 2 For encrypt() the msg_len would need to be > SIZE_MAX - 16U For aes256gcm_encrypt_afternm() the msg_len would need to be > SIZE_MAX - 16U For seal() the enc_len would need to be > SIZE_MAX - 64U

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypt\

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-08); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
crypt\

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-08: 2Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0803-0903-1203-13
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-082
Disclosure2
2026-03-091
Disclosure1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-30909: Crypt::NaCl::Sodium versions through 2.002 has potential integer overflows https://www.openwall.com/lists/oss-security/2026/03/08/1 CVE-2026-30910: Crypt::Sodium::XS versions through 0.001000 has potential integer overflows https://www.openwall.com/lists/oss-security/2026/03/08/2

    Post summary

    The text announces two integer overflow vulnerabilities (CVE‑2026‑30909 and CVE‑2026‑30910) affecting Perl CPAN modules, with links to mailing list discussions for further details.

    00031265
    4.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30909 (CVSS:9.8, CRITICAL) is Undergoing Analysis. Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encryp..https://nvd.nist.gov/vuln/detail/CVE-2026-30909 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-30909 with a high CVSS score and integer overflow risk in Crypt::NaCl::Sodium (<=2.002), but provides no PoC, exploit, or patch details.

    0000022
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30909 (CVSS:9.8, CRITICAL) is Undergoing Analysis. Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encryp..https://nvd.nist.gov/vuln/detail/CVE-2026-30909 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑30909 as a critical integer‑overflow vulnerability in Crypt::NaCl::Sodium for Perl, referencing NVD for details.

    0000029
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30909 Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that… https://www.cve.org/CVERecord?id=CVE-2026-30909

    Post summary

    The statement reports CVE‑2026‑30909, indicating an integer overflow flaw in the Crypt::NaCl::Sodium Perl library (functions bin2hex, encrypt, aes256gcm_encrypt_afternm, and seal) for versions up to 2.002, with no mention of exploitation or fixes.

    00000120
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30909 - Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows Intel Report: https://ift.tt/DA7zR2x

    Post summary

    Alert announces CVE-2026-30909, an integer‑overflow issue in Crypt::NaCl::Sodium for Perl, with reference to an Intel report for details.

    0000034
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptimleggecrypt\\--

Explore more