SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-87736

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The mirage-crypto-ec package prior to version 2.3.0 for OCaml is vulnerable to an out-of-bounds read when handling EC public keys for compressed points, which could potentially lead to information disclosure. This vulnerability poses a medium risk and should be prioritized by developers and organizations utilizing this package to ensure the integrity and confidentiality of cryptographic operations.

CVE
CVE-2026-87736
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.