Libsodium’s First Vulnerability, Ever - Threat Wire
Quick Overview
The Libsodium encryption library, trusted for 13 years, announced its first-ever critical vulnerability, CVE-2025-69277, stemming from a missing check in its Edwards 25519 elliptic curve point validation function, prompting the creator to recommend switching to the restredto 255 group.
Key Points: Libsodium, an encryption library used for 13 years without incident, announced its first vulnerability, CVE-2025-69277, on December 30, 2025. The bug, rated with a base CVSS score of 4.5 by MITER, resulted from a missing subtraction and an is zero check when validating elliptic curve points in the Edwards 25519 implementation. The creator discovered the flaw while comparing Zigg and C implementations of the library and recommends users move to the restredto 255 group which is faster and requires no extra point checks. Four critical severity CVEs were announced for the NATN workflow automation tool within a two-week period, including two with perfect 10 CVSS scores (CVE-2026-21877 and CVE-2026-21858). One unauthenticated NATN vulnerability, CVE-2026-21858 ('nightmare'), allows reading local files and achieving RCE by overwriting the file handling function body due to failure to verify content type on a webhook call. California implemented the DROP Act on January 1st, 2026, allowing residents to submit universal deletion requests to data brokers via a government website, addressing the underutilization of the previous Delete Act. Anonymous hacker Martha Root gained notoriety for infiltrating three white supremacy dating sites, exfiltrating user data, taking the sites offline in real-time during a CCC talk, and sharing data with DOS Secrets.
Context: This weekly cybersecurity review from early 2026, hosted by Alli Diamond on Threatwire, covers several major security and privacy developments including new California digital privacy laws, a major security crisis affecting the NATN workflow automation tool, the first-ever vulnerability in the Libsodium encryption library, and a high-profile hack against hate groups detailed at the Chaos Communication Congress.