SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-89087

HIGH · CVSS 7.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The cstruct package prior to version 6.3.0 for OCaml is vulnerable due to improper handling of indexes, which could lead to potential memory corruption or data leakage. This high-severity vulnerability poses significant risks for applications relying on this package, making it crucial for developers and organizations using OCaml to prioritize updates to mitigate potential exploitation.

CVE
CVE-2026-89087
Severity
HIGH
CVSS
7.3
EPSS
0.19%

Original NVD Description

The cstruct package before 6.3.0 for OCaml mishandles indexes.