SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-87737

MEDIUM · CVSS 5.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The mirage-crypto-ec package prior to version 2.4.0 for OCaml is vulnerable to a timing side channel attack during NIST elliptic-curve scalar multiplication, where the time taken for a lookup may reveal secret information. This could potentially allow an attacker to exploit the timing variations to recover sensitive cryptographic keys. Organizations using this package should prioritize upgrading to version 2.4.0 or later to mitigate the risk of key exposure.

CVE
CVE-2026-87737
Severity
MEDIUM
CVSS
5.9
EPSS
0.21%

Original NVD Description

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.