Vulnerabilities
Summary — last 7 days
New vulnerabilities2,744▼ 71 vs. last week
Critical / high1,416▲ 184 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)106▼ 394 vs. last week
17 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.1) | 0.28% | — | JoseAIOcamlAI | 9/10/2026 | 9/22/2026 | In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key. | |
| Deferred | Medium (5.7) | 0.47% | — | Ocaml OpamAI | 9/9/2026 | 9/14/2026 | In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files. | |
| Deferred | Critical (9.1) | 0.52% | — | Ocaml TARAI | 6/15/2026 | 6/17/2026 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction… | |
| Deferred | High (7.4) | 0.25% | — | Ocaml-tlsAI | 6/15/2026 | 6/17/2026 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage). | |
| Deferred | Critical (9.1) | 0.31% | — | Ocaml-tlsAI | 6/15/2026 | 6/17/2026 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage). | |
| Analyzed | High (7.8) | 0.22% | — | Ocaml OpamDebian LinuxRedhat Enterprise Linux | 4/16/2026 | 7/15/2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | |
| Analyzed | Medium (5.1) | 0.15% | — | Ocaml | 3/27/2026 | 6/17/2026 | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed. | |
| Modified | High (7.8) | 0.32% | — | Ocaml | 2/27/2026 | 7/15/2026 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using… | |
| Modified | Critical (9.8) | 4.1% | — | Ocaml | 4/6/2018 | 6/17/2026 | The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a… | |
| Modified | High (8.8) | 1.2% | — | Ocaml Batteries Project Ocaml Batteries | 12/14/2017 | 6/17/2026 | batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. | |
| Modified | High (7.8) | 0.58% | — | Ocaml | 9/7/2017 | 6/17/2026 | OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact." | |
| Modified | Critical (9.8) | 3.5% | — | Ocaml | 6/23/2017 | 6/17/2026 | Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variable. | |
| Modified | Critical (9.1) | 5.3% | — | Fedoraproject FedoraOpensuseOcaml | 6/13/2016 | 6/17/2026 | OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function. | |
| Modified | Medium (5) | 1.5% | — | Nicolas Cannasse Ocaml Xml-light Library | 8/25/2012 | 6/16/2026 | OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via unspecified vectors. | |
| Modified | Medium (5) | 2.7% | — | Inria Ocaml | 2/8/2012 | 6/16/2026 | OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. | |
| Modified | High (7.5) | 2.2% | — | Postgresql-ocaml | 10/22/2009 | 6/16/2026 | The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. | |
| Modified | High (7.5) | 2.3% | — | Mysql-ocaml | 10/22/2009 | 6/16/2026 | The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings. |