CVE-2026-2588: Timlegge Crypt::nacl::sodium
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bits while an unsigned long long is at least 64-bits.
Affected products
- Timlegge Crypt::nacl::sodium: up to and including 2.001
Published 2026-02-23. Last modified 2026-06-17.