CVE-2026-30910Disclosure(iamb / crypt\)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combined signature creation, and bin2hex functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing an undersized output buffer. This can cause a crash in bin2hex and encryption algorithms other than aes256gcm. For aes256gcm encryption and signatures, an undersized buffer could lead to buffer overflow. Encountering this issue is unlikely as the message length would need to be very large. For bin2hex the input size would have to be > SIZE_MAX / 2 For aegis encryption the input size would need to be > SIZE_MAX - 32U For other encryption the input size would need to be > SIZE_MAX - 16U For signatures the input size would need to be > SIZE_MAX - 64U

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypt\

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-08); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
crypt\

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-08: 3Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-08: 3Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0803-0903-1203-13
Signal classification1 categories
Disclosure
6100.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-083
Disclosure3
2026-03-091
Disclosure1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-30909: Crypt::NaCl::Sodium versions through 2.002 has potential integer overflows https://www.openwall.com/lists/oss-security/2026/03/08/1 CVE-2026-30910: Crypt::Sodium::XS versions through 0.001000 has potential integer overflows https://www.openwall.com/lists/oss-security/2026/03/08/2

    Post summary

    The notice reports integer overflow vulnerabilities in two Perl CPAN modules, detailing affected versions and linking to further discussion.

    00031265
    4.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30910 (CVSS:7.5, HIGH) is Modified. Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combine..https://nvd.nist.gov/vuln/detail/CVE-2026-30910 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a modified CVE-2026-30910, providing basic technical details such as CVSS score and the affected Perl module, but does not mention a PoC, exploit, active use, or patch.

    0000019
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30910 (CVSS:7.5, HIGH) is Modified. Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combine..https://nvd.nist.gov/vuln/detail/CVE-2026-30910 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces CVE‑2026‑30910 as a modified integer‑overflow vulnerability in Crypt::Sodium::XS with a high CVSS score, without providing PoC, exploit code, active exploitation evidence, or patch information.

    0000020
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30910 Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combined signature creation, and bin2hex functions do… https://www.cve.org/CVERecord?id=CVE-2026-30910

    Post summary

    The tweet announces CVE‑2026‑30910, noting integer overflow vulnerabilities in Crypt::Sodium::XS, but provides no evidence of exploits, patches, or mitigation steps.

    00000116
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30910 - Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows Intel Report: https://ift.tt/gJm41H8

    Post summary

    A new integer overflow vulnerability (CVE-2026-30910) affecting Crypt::Sodium::XS (Perl) has been reported, with a link to an Intel Report.

    0000036
    347 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30910 Integer Overflow Vulnerability in Crypt::Sodium::XS Perl Module Through ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30910 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-30910 as an integer overflow in the Crypt::Sodium::XS Perl Module, providing only the basic vulnerability details without PoC, exploit code, or patch information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiambcrypt\\--

Explore more