Vulnerabilidades en OCaml
3 resultadosAnálisis Vexday
OCaml apresenta um perfil de risco baixo com apenas 3 CVEs registradas, nenhuma explorada ativamente nem classificada como crítica. A vulnerabilidade dominante é do tipo CWE-125 (leitura além dos limites), porém sem descobertas recentes, indicando estabilidade relativa da plataforma.
CVE-2026-28364HIGHIn OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution EPSS 0.2%CVE-2026-41082HIGHIn OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.EPSS 0.2%CVE-2026-34353MEDIUMIn OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is procEPSS 0.1%