Description
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.
Published: 2026-09-09
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Forged Tag
Action: Immediate Patch
AI Analysis

Impact

A flaw in mirage-crypto’s decrypt functions causes the decrypted plaintext to be written into a caller‑supplied buffer before the authentication tag is checked. When the tag is forged, the functions return false, yet the buffer still contains the full plaintext. This results in inadvertent information disclosure, exposing sensitive data without proper authentication, and exemplifies CWE‑347.

Affected Systems

The vulnerability affects the mirage-crypto library for OCaml. All releases before version 2.2.0 are impacted, including the specific AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity, although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply forged ciphertext and tags, which can be achieved locally if the library is used in an untrusted context or remotely if the decryption routine is exposed through an application interface. The attack ultimately retrieves plaintext data, compromising confidentiality but not privilege levels or availability.

Generated by OpenCVE AI on September 9, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade mirage‑crypto to version 2.2.0 or later where the decryption order is corrected.
  • Modify application code to verify the authentication tag before processing or exposing the plaintext returned by the decrypt functions, ensuring the buffer content is not used when verification fails.
  • If an upgrade is not immediately feasible, wrap the existing functions with a custom check that first validates the tag or replace the library call with a vetted cryptographic routine that guarantees correct tag verification before any plaintext is returned.

Generated by OpenCVE AI on September 9, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ocaml
Ocaml mirage-crypto-pk
Vendors & Products Ocaml
Ocaml mirage-crypto-pk

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Potential Plaintext Exposure from Forged Tag in Mirage-Crypto AES/GCM and ChaCha20 Decrypt Functions

Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ocaml Mirage-crypto-pk
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T13:11:54.773Z

Reserved: 2026-09-09T04:03:52.629Z

Link: CVE-2026-87732

cve-icon Vulnrichment

Updated: 2026-09-09T13:11:51.667Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T05:18:20.277

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-87732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:36Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature