CVE-2026-87737: Ocaml Mirage-Crypto-Ec

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

Affected products

  • Ocaml Mirage-Crypto-Ec: before 2.4.0 (fixed in 2.4.0)

Published 2026-09-09. Last modified 2026-09-09.