Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
OSEC-2026-17
  • github.com/mirage/mirage-crypto
  • opam/mirage-crypto-ec
Timing leak in NIST elliptic curves scalar multiplication yesterday
  • Fix available
  • Severity - 5.9 (Medium)
OSEC-2026-14
  • github.com/mirage/mirage-crypto.git
  • opam/mirage-crypto-pk
RSA signature verification raises undocumented exception 07 Aug
  • Fix available
  • Severity - 4.3 (Medium)
OSEC-2026-15
  • github.com/mirage/mirage-crypto.git
  • opam/mirage-crypto-ec
EC public key out of bounds read 07 Aug
  • Fix available
  • Severity - 4.3 (Medium)
OSEC-2026-11
  • git.robur.coop/robur/utcp.git
  • opam/utcp
Out of order segment reassembly allows remote denial of service 27 Jul
  • Fix available
  • Severity - 7.5 (High)
OSEC-2026-12
  • github.com/mirage/mirage-crypto.git
  • opam/mirage-crypto
AEAD `decrypt_into` functions writes plaintext before checking the tag 27 Jul
  • Fix available
  • Severity - 6.2 (Medium)
OSEC-2026-13
  • github.com/mirage/mirage-crypto.git
  • opam/mirage-crypto-ec
ECDSA accepts the point at infinity as a P256, P384, P521 public key 27 Jul
  • Fix available
  • Severity - 6.2 (Medium)
OSEC-2026-10
  • github.com/ocaml/opam
  • opam/opam-devel
opam install sandbox escape using symlinks 07 Jul
  • Fix available
  • Severity - 5.7 (Medium)
OSEC-2026-05
  • github.com/ocaml/ocaml
  • opam/ocaml
Windows command execution via filename quotes. 18 Jun
  • Fix available
  • Severity - 6.1 (Medium)
OSEC-2026-04
  • github.com/ocaml/ocaml
  • opam/ocaml
Bigarray.reshape integer overflow 18 Jun
  • Fix available
  • Severity - 6.1 (Medium)
OSEC-2026-09
  • git.robur.coop/robur/albatross.git
  • opam/albatross
Albatross-console memory exhaustion 28 May
  • Fix available
  • Severity - 4.9 (Medium)
OSEC-2026-08
  • github.com/mirage/ocaml-tar
  • opam/tar
Path traversal vulnerability in ocaml-tar 22 May
  • Fix available
  • Severity - 8.2 (High)
OSEC-2026-06
  • github.com/mirleft/ocaml-tls
  • opam/tls
TLS-client (with TLS 1.3) does insufficient certificate checks (missing KeyUsage and ExtendedKeyUsage validation) 20 May
  • Fix available
  • Severity - 7.4 (High)
OSEC-2026-07
  • github.com/mirleft/ocaml-tls
  • opam/tls
TLS-server does insufficient client certificate checks (missing KeyUsage and ExtendedKeyUsage validation) 20 May
  • Fix available
  • Severity - 7.4 (High)
OSEC-2026-03
  • github.com/ocaml/opam
  • opam/opam-devel
opam install sandbox escape 15 Apr
  • Fix available
  • Severity - 5.7 (Medium)
OSEC-2026-02
  • github.com/mirage/arp
  • opam/arp
ARP unbounded memory usage 18 Feb
  • Fix available
  • Severity - 7.4 (High)
OSEC-2026-01
  • github.com/ocaml/ocaml
  • opam/ocaml
Buffer Over-Read in OCaml Marshal Deserialization 17 Feb
  • Fix available
  • Severity - 6.8 (Medium)