CVE-2026-87735: Medium severity npm/mirage-crypto-pk vulnerability
Published Sep 9, 2026
·Updated
An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.
Affected Software
1 affected component
npm/mirage-crypto-pk<2.3.0
Event History
Sep 9, 2026
CVE Published
via MITRE·04:16 AM
Data Sourced
via MITRE·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to trigger the issue?
The vulnerability is remotely reachable and has low attack complexity, but the attacker must have low-level privileges. No user interaction is required.
2
What is the impact of successful exploitation?
The reported impact is limited to availability: confidentiality and integrity are not affected, while availability is rated low. The issue involves an undocumented exception for a small message during RSA decryption or encryption.
3
Which package versions should be remediated?
The affected package is npm/mirage-crypto-pk before version 2.3.0. Updating to 2.3.0 or later addresses the affected version range.