CVE-2026-89087: High severity ocaml/cstruct vulnerability
Published Sep 10, 2026
·Updated
The cstruct package before 6.3.0 for OCaml mishandles indexes.
Affected Software
1 affected component
ocaml/cstruct<6.3.0
Event History
Sep 10, 2026
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be treated as affected?
Deployments using the OCaml cstruct package at versions earlier than 6.3.0 should be treated as affected. Version 6.3.0 is the first version identified as not affected.
2
What level of attacker access is indicated by the severity vector?
The vector indicates network-reachable exploitation with low attack complexity, requiring no privileges and no user interaction. The actual reachable attack surface depends on whether an application exposes functionality that uses cstruct to untrusted network input.
3
What impact is indicated if exploitation succeeds?
The supplied vector rates confidentiality, integrity, and availability impact as low. The overall severity is high with a CVSS score of 7.3.