An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.
References
| Link | Resource |
|---|---|
| https://osv.dev/vulnerability/OSEC-2026-17 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 05:18
Updated : 2026-09-09 16:04
NVD link : CVE-2026-87737
Mitre link : CVE-2026-87737
CVE.ORG link : CVE-2026-87737
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
