https://seclists.org/oss-sec/2026/q1/231: OSEC-2026-01 in the OCaml runtime: Buffer Over-ad in OCaml Marshal Deserialization
Published Feb 27, 2026
·Updated
Affected Software
1 affected component
ocaml<4.14.3, >=5<5.4.1
OCaml versions earlier than 4.14.3 are affected. In the 5.x series, versions from 5.0 up to, but not including, 5.4.1 are affected.
The CVSS vector rates the attack as local, with low attack complexity and no privileges or user interaction required. It rates confidentiality impact as high, integrity impact as low, and availability impact as none.
Check the OCaml runtime version in use. Installations below 4.14.3, or running a 5.x version below 5.4.1, are affected.