CVE-2026-87732
Deferred Deferred - Pending Action

Mirage Crypto OCaml AES-GCM Plaintext Leak Before 2.2.0

Vulnerability report for CVE-2026-87732, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: MITRE

Description

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mirage mirage-crypto to 2.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the mirage-crypto package before version 2.2.0 for OCaml. The issue is in the AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions. These functions decrypt data into a buffer provided by the caller and then verify the authentication tag. If the tag is forged, the functions return false but the decrypted plaintext remains in the buffer, potentially exposing sensitive data.

Detection Guidance

This vulnerability is specific to the mirage-crypto OCaml package and does not have direct network or system detection methods. You should check if your system uses the vulnerable version of mirage-crypto (before 2.2.0) by inspecting installed packages. For OCaml projects, use commands like 'opam list mirage-crypto' to verify the version.

Impact Analysis

An attacker could exploit this to decrypt ciphertext without knowing the correct key by providing a forged tag. This could lead to unauthorized access to decrypted data, even though the system reports decryption failure. The impact includes potential exposure of sensitive information stored or transmitted using these cryptographic functions.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure encryption and protection of sensitive data. For example, GDPR requires appropriate technical measures to ensure data security, and HIPAA mandates encryption for protected health information. Failure to properly decrypt data could result in unauthorized access, leading to potential regulatory penalties.

Mitigation Strategies

Immediately upgrade the mirage-crypto package to version 2.2.0 or later. If you are using OCaml with opam, run 'opam update' followed by 'opam upgrade mirage-crypto'. Review any applications using this library to ensure they are recompiled with the updated version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87732. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart