Sale of 10 zero-day vulnerabilities in the libsodium library

Dark Web2026-06-22, 08:49
For informational purposes only
Affected versions: up to 1.0.22 Price: 200 BTC (~64K)
According to the author, one of the exploits is used for a remote DoS attack against the crypto_box_open_easy function in libsodium, triggered by passing boundary size values (SIZE_MAX and SIZE_MAX-1). The error causes the server to crash with SIGSEGV, making it possible to cause a denial of service without additional access.
In addition, the presence of several other zero-day vulnerabilities is mentioned, including out-of-heap reads and Nonce reuse exploitation, affecting both supported cryptographic libraries. Launching the attacks requires the ability to send specially crafted input data. As a result, the attacker can cause a denial of service or application memory leakage.
Products
Crypto_Box_Open_Easy
Libsodium