Undocumented Exception in RSA Mechanism in Mirage Crypto PK Package
CVE-2026-87735

4.3MEDIUM

Key Information:

Vendor

Ocaml

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87735?

A security issue found in the mirage-crypto-pk package prior to version 2.3.0 can lead to unexpected behaviors during RSA encryption and decryption. This vulnerability arises from an undocumented exception triggered by small messages, potentially allowing for unauthorized access or manipulation of cryptographic operations. It underscores the importance of using the latest version to ensure secure handling of cryptographic functions.

Affected Version(s)

mirage-crypto-pk 0 < 2.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.