Vendor
OCaml vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in OCaml: 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-89087, was published on 10 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 0
- Exploited in the wild
- 0
About OCaml
The OCaml community and core development team maintain the OCaml programming language and its ecosystem.
OCaml technologies
Latest OCaml vulnerabilities
- CVE-2026-89087: cstruct indexing bugs in filter_map, tail, cuts, and findhighCVSS 7.3EPSS 0.3%
- CVE-2026-87737: mirage-crypto-ec timing side channel in NIST elliptic-curve scalar multiplicationmediumCVSS 5.9EPSS 0.3%
- CVE-2026-87736: Mirage-Crypto-EC out-of-bounds read in EC public key parsingmediumCVSS 4.3EPSS 0.4%
- CVE-2026-87734: utcp out-of-order segment reassembly denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-87733: Mirage-crypto-ec ECDSA signature forgery via point at infinitymediumCVSS 6.2EPSS 0.1%
- CVE-2026-57825: opam sandbox escape using symlinks in .install filesmediumCVSS 5.7EPSS 0.5%
- CVE-2026-82481: OCaml cohttp directory traversal via URL decodinginfoEPSS 0.7%
- CVE-2026-41082: OCaml opam path traversal in .install fieldhighCVSS 7.3EPSS 0.2%
- CVE-2026-28364: OCaml Marshal deserialization buffer over-read in runtime/intern.chighCVSS 7.9EPSS 0.2%
Most severe OCaml vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-28364: OCaml Marshal deserialization buffer over-read in runtime/intern.chighCVSS 7.9EPSS 0.2%
- CVE-2026-87734: utcp out-of-order segment reassembly denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-89087: cstruct indexing bugs in filter_map, tail, cuts, and findhighCVSS 7.3EPSS 0.3%
- CVE-2026-41082: OCaml opam path traversal in .install fieldhighCVSS 7.3EPSS 0.2%
- CVE-2026-87733: Mirage-crypto-ec ECDSA signature forgery via point at infinitymediumCVSS 6.2EPSS 0.1%
- CVE-2026-87737: mirage-crypto-ec timing side channel in NIST elliptic-curve scalar multiplicationmediumCVSS 5.9EPSS 0.3%
- CVE-2026-57825: opam sandbox escape using symlinks in .install filesmediumCVSS 5.7EPSS 0.5%
- CVE-2026-87736: Mirage-Crypto-EC out-of-bounds read in EC public key parsingmediumCVSS 4.3EPSS 0.4%
- CVE-2026-82481: OCaml cohttp directory traversal via URL decodinginfoEPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 6 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/ocaml.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OCaml vulnerabilities", https://junglewise.ai/threats/vendors/ocaml, 26 September 2026.