CVE-2026-87733: Ocaml Mirage-Crypto-Ec

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.

Affected products

  • Ocaml Mirage-Crypto-Ec: before 2.2.0 (fixed in 2.2.0)

Published 2026-09-09. Last modified 2026-09-09.