CVE-2026-87737
Deferred Deferred - Pending Action

Timing Side Channel in Mirage Crypto EC for OCaml

Vulnerability report for CVE-2026-87737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: MITRE

Description

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mirage mirage-crypto-ec to 2.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a timing side channel in the mirage-crypto-ec package before version 2.4.0 for OCaml. It involves NIST elliptic-curve scalar multiplication where the time taken for a lookup operation can depend on secret data, potentially allowing attackers to extract sensitive information through timing analysis.

Detection Guidance

This vulnerability involves a timing side channel in NIST elliptic-curve scalar multiplication in the mirage-crypto-ec package. Detection requires checking the installed version of mirage-crypto-ec and verifying if it is below 2.4.0. Use commands like 'opam list mirage-crypto-ec' or 'opam show mirage-crypto-ec' to inspect the version. If the version is older than 2.4.0, the system is vulnerable.

Impact Analysis

If you use the affected mirage-crypto-ec package, an attacker could exploit this timing side channel to gain unauthorized access to secret cryptographic keys or other sensitive data processed by the library. This could lead to data breaches or compromise of encrypted communications.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations that require protection of personal or health data. A breach due to this issue may result in legal penalties, loss of trust, and failure to meet data protection standards.

Mitigation Strategies

Update the mirage-crypto-ec package to version 2.4.0 or later to address the timing side channel vulnerability in NIST elliptic-curve scalar multiplication.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart