
PEACH
Un framework di isolamento del tenant
CVE-2026-87735 is a denial-of-service vulnerability in the mirage-crypto-pk package for OCaml, caused by an undocumented exception triggered when processing small messages during RSA decryption or encryption operations. It affects all versions of mirage-crypto-pk before 2.3.0. The vulnerability was published on September 9, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input): the library fails to validate or properly handle message size inputs before passing them to RSA cryptographic operations, resulting in an undocumented exception being raised for unexpectedly small messages. An authenticated, network-accessible attacker can trigger this exception by submitting a crafted small message to any service endpoint that invokes mirage-crypto-pk's RSA encrypt or decrypt functions. No public proof-of-concept code has been identified at this time (GitHub Advisory, OSV).
Successful exploitation causes the RSA encryption or decryption operation to raise an unhandled exception, which can crash the affected cryptographic service or cause the operation to fail entirely, resulting in a loss of availability. The impact is limited to availability (low severity per CVSS), with no confidentiality or integrity compromise. Services built on mirage-crypto-pk that expose RSA operations to authenticated users are at risk of disruption, but lateral movement or data exfiltration are not direct consequences of this vulnerability (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-87735. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability requires low-privilege authenticated access over the network, which somewhat limits the attack surface. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
Upgrade the mirage-crypto-pk package to version 2.3.0 or later, which resolves the undocumented exception. As a complementary measure, implement input validation at the application layer to reject or sanitize unexpectedly small messages before they are passed to RSA operations. Adding exception handling around RSA encrypt/decrypt calls can also help prevent service crashes in the interim (GitHub Advisory).
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
bookworm
ocaml-mirage-crypto
sid
ocaml-mirage-crypto: 2.3.0-1
trixie
ocaml-mirage-crypto
devel
ocaml-mirage-crypto
jammy
ocaml-mirage-crypto
jammy (esm-apps)
ocaml-mirage-crypto
noble
ocaml-mirage-crypto
noble (esm-apps)
ocaml-mirage-crypto
resolute
ocaml-mirage-crypto
resolute (esm-apps)
ocaml-mirage-crypto
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."