CVE-2026-87732
An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- CWE
- CWE-347
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- OCaml mirage-crypto
Weakness type
Related vulnerabilities
- CVE-2023-54355 — PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve
- CVE-2026-79970 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-56207 — Apache Impala: SAML authentication bypass via forged bearer token
- CVE-2026-86080 — n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
- CVE-2026-69646 — Skype for Business Spoofing Vulnerability
- CVE-2026-57098 — Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
- CVE-2026-14296 — nRF54H20: MCUBoot can be tricked to executing unauthenticated code
- CVE-2026-86304 — MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor