CVE-2026-89087
The cstruct package before 6.3.0 for OCaml mishandles indexes.
- Published Sep 10, 2026
- CVSS 7.3 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available
The cstruct package before 6.3.0 for OCaml mishandles indexes.