CVE-2012-3514: Nicolas Cannasse Ocaml XML-Light Library
Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.
OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via unspecified vectors.
Affected products
- Nicolas Cannasse Ocaml XML-Light Library: up to and including r233
Published 2012-08-25. Last modified 2026-06-16.