CVE-2026-82481: Mirage Cohttp

High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.

The cohttp package before 6.3.0 for OCaml allows directory traversal.

Affected products

  • Mirage Cohttp: before 6.3.0 (fixed in 6.3.0)

Published 2026-08-29. Last modified 2026-09-01.