Timing Side Channel Vulnerability in Mirage-Crypto-EC Package for OCaml
CVE-2026-87737

5.9MEDIUM

Key Information:

Vendor

Ocaml

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87737?

The mirage-crypto-ec package for OCaml is susceptible to a timing side channel vulnerability that affects its NIST elliptic-curve scalar multiplication implementation. This issue arises from the fact that the time taken for certain operations may vary based on a secret value, leading to the potential exposure of sensitive information. This vulnerability exists in versions prior to 2.4.0, making it crucial for users to update to the latest version to mitigate the associated risks.

Affected Version(s)

mirage-crypto-ec 0 < 2.4.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.