Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-89087

Medium priority
Needs evaluation

The cstruct package before 6.3.0 for OCaml mishandles indexes.

1 affected package

ocaml-cstruct

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-cstruct Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87737

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87736

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87735

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87733

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key,...

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87732

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and...

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-82481

Medium priority
Needs evaluation

The cohttp package before 6.3.0 for OCaml allows directory traversal.

1 affected package

ocaml-cohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-cohttp Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-67216

Medium priority
Vulnerable

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mapcache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sail-ocaml Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-34353

Medium priority
Needs evaluation

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

1 affected package

ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28364

Medium priority
Needs evaluation

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation...

1 affected package

ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages