
PEACH
Un framework di isolamento del tenant
CVE-2026-87737 is a timing side-channel vulnerability in the mirage-crypto-ec package for OCaml, affecting all versions before 2.4.0. The flaw exists in NIST elliptic-curve scalar multiplication, where the time required for a lookup operation can vary based on a secret value, potentially leaking cryptographic key material. It was published on September 9, 2026, and carries a CVSS v3.1 base score of 5.9 (Medium) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-208 (Observable Timing Discrepancy), arising from non-constant-time execution during table lookups in NIST elliptic-curve scalar multiplication within the mirage-crypto-ec library. An unauthenticated remote attacker can exploit this by repeatedly invoking cryptographic operations and measuring response times to statistically infer secret scalar values — a classic timing side-channel attack. No special privileges or user interaction are required, though exploitation requires high attack complexity due to the statistical nature of timing analysis. The vulnerability is also mapped to CAPEC-462 (Cross-Domain Search Timing) (GitHub Advisory, OSV).
Successful exploitation allows an unauthenticated network attacker to extract secret cryptographic key material from applications using the vulnerable mirage-crypto-ec library through timing analysis of elliptic-curve operations. The impact is limited to confidentiality — integrity and availability are not affected — but exposure of private keys could enable impersonation, decryption of protected communications, or compromise of TLS sessions depending on how the library is used in the target application (GitHub Advisory, Feedly).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting a very low probability of near-term exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity, as it depends on the ability to perform precise, repeated timing measurements of cryptographic operations over a network.
The primary remediation is to upgrade the mirage-crypto-ec package to version 2.4.0 or later, which addresses the non-constant-time lookup issue in NIST elliptic-curve scalar multiplication (GitHub Advisory). If immediate patching is not possible, consider implementing network-level mitigations such as rate limiting or jitter on cryptographic operation responses to reduce timing measurement precision. Applications relying on this library for TLS or key exchange should be prioritized for patching given the potential for key material exposure.
The vulnerability received limited public attention at the time of disclosure, with automated CVE tracking services (VulDB, CVEFeed, cve.report) and a Bluesky post from a CVE monitoring account being the primary sources of coverage (Feedly). No notable researcher commentary or vendor statements beyond the GitHub Advisory Database entry have been identified.
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
bookworm
ocaml-mirage-crypto
sid
ocaml-mirage-crypto: 2.4.0-1
trixie
ocaml-mirage-crypto
devel
ocaml-mirage-crypto
jammy
ocaml-mirage-crypto
jammy (esm-apps)
ocaml-mirage-crypto
noble
ocaml-mirage-crypto
noble (esm-apps)
ocaml-mirage-crypto
resolute
ocaml-mirage-crypto
resolute (esm-apps)
ocaml-mirage-crypto
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."