CyberRota Analysis
AI-GeneratedThe mirage-crypto-ec package prior to version 2.3.0 for OCaml is vulnerable to an out-of-bounds read when handling EC public keys for compressed points, which could potentially lead to information disclosure. This vulnerability poses a medium risk and should be prioritized by developers and organizations utilizing this package to ensure the integrity and confidentiality of cryptographic operations.
CVE
CVE-2026-87736
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%
Original NVD Description
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.