Vulnerabilities in OCaml

12 results
Vexday analysis

OCaml apresenta um perfil de risco baixo com apenas 3 CVEs registradas, nenhuma explorada ativamente nem classificada como crítica. A vulnerabilidade dominante é do tipo CWE-125 (leitura além dos limites), porém sem descobertas recentes, indicando estabilidade relativa da plataforma.

CVE-2026-87734HIGHAn issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.EPSS 0.5%CVE-2026-57825MEDIUMIn the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .EPSS 0.5%CVE-2026-87736MEDIUMAn issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed EPSS 0.4%CVE-2026-87737MEDIUMAn issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalaEPSS 0.3%CVE-2026-28364HIGHIn OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution EPSS 0.3%CVE-2026-89087HIGHThe cstruct package before 6.3.0 for OCaml mishandles indexes.EPSS 0.3%CVE-2026-89086CRITICALIn the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proEPSS 0.3%CVE-2026-87735MEDIUMAn issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message durinEPSS 0.2%CVE-2026-41082HIGHIn OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.EPSS 0.2%CVE-2026-87733MEDIUMAn issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets acceEPSS 0.2%CVE-2026-34353MEDIUMIn OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is procEPSS 0.1%CVE-2026-87732MEDIUMAn issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticateEPSS 0.1%