Description
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read of compressed EC public key
Action: Assess
AI Analysis

Impact

The vulnerability arises in the mirage-crypto-ec library prior to version 2.3.0 when a compressed elliptic-curve public key is processed. An out-of-bounds memory read can occur if the key data lies beyond the allocated buffer, potentially exposing arbitrary memory contents. The weakness is classified as CWE-125, a classic out-of-bounds read, which can lead to information disclosure or application crashes.

Affected Systems

OCaml mirage-crypto-ec, any version before 2.3.0. Any program that uses the library to parse compressed EC points is affected.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate impact. EPSS is not available, so the likelihood of exploitation is unclear. The vulnerability is not listed in CISA KEV. Without a clear remote exploitation path, the attacker must supply a crafted EC point to trigger the read, typically by sending crafted data to a service that processes EC keys. The primary consequence is information disclosure or denial of service, rather than remote code execution.

Generated by OpenCVE AI on September 9, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade mirage-crypto-ec to 2.3.0 or later.
  • Validate input lengths before passing EC points to the library.
  • Implement defensive checks to ensure the point buffer does not exceed boundaries in any custom wrappers.

Generated by OpenCVE AI on September 9, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ocaml
Ocaml mirage-crypto-ec
Vendors & Products Ocaml
Ocaml mirage-crypto-ec

Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title EC Public Key Out-of-Bounds Read in Mirage‑Crypto‑EC

Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ocaml Mirage-crypto-ec
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:41:32.129Z

Reserved: 2026-09-09T04:18:59.766Z

Link: CVE-2026-87736

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:52.940Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T05:18:20.873

Modified: 2026-09-14T16:17:21.733

Link: CVE-2026-87736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:31Z

Weaknesses