CVE-2025-40914Dependency on Vulnerable Third-Party Component in Libcryptx-perl

Severity
9.8CRITICALNVD
EPSS
0.5%
top 32.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMar 26

Description

Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
OSV
libcryptx-perl vulnerabilities2026-03-26
OSV
CVE-2025-40914: Perl CryptX before version 02025-06-11

📋Vendor Advisories

3
Ubuntu
CryptX vulnerabilities2026-03-26
Microsoft
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow2025-06-10
Debian
CVE-2025-40914: libcryptx-perl - Perl CryptX before version 0.087 contains a dependency that may be susceptible t...2025
CVE-2025-40914 — Debian Libcryptx-perl vulnerability | cvebase