Junglewise Threat Intelligence

CVE-2026-87735: mirage-crypto-pk RSA undocumented exception handling in decrypt/encrypt

CVE-2026-87735 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Executive brief

mirage-crypto-pk is a cryptographic library for OCaml used to perform RSA encryption, decryption, and signature operations. The library raises an undocumented exception when processing very small messages (0 or 1 byte), which can cause X.509 certificate validation to fail unexpectedly instead of returning a proper error, potentially disrupting certificate verification workflows in applications relying on this library.

Technical details

The RSA decrypt and encrypt functions in mirage-crypto-pk raise an undocumented Invalid_argument exception when the message size is smaller than 2 bytes. This is a improper exception handling issue (CWE-248) that affects RSA operations including PKCS1 encoding/decoding, OAEP encryption/decryption, and PSS signing/verification. When processing X.509 certificates with signature values of 0 or 1, the library throws this uncaught exception rather than returning a documented error. The vulnerability is exploitable by an authenticated attacker who can supply crafted RSA inputs, and causes denial of service through unhandled exceptions in certificate validation. The fix, released in version 2.3.0 (August 7, 2026), replaces the undocumented exception with the documented Insufficient_key exception.

Affected products

  • Mirage mirage-crypto-pk before 2.3.0

Timeline

  • 2026-07-28: disclosed: Report to security@ocaml.org
  • 2026-08-07: patched: Release of mirage-crypto-pk 2.3.0 with security fix
  • 2026-09-09: advisory: CVE-2026-87735 published