Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://osv.dev/vulnerability/OSEC-2026-17 |
|
Wed, 09 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Timing Side Channel in NIST Elliptic‑Curve Scalar Multiplication |
Wed, 09 Sep 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret. | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-09T13:10:11.317Z
Reserved: 2026-09-09T04:21:37.242Z
Link: CVE-2026-87737
Updated: 2026-09-09T13:10:07.200Z
Status : Deferred
Published: 2026-09-09T05:18:21.020
Modified: 2026-09-09T16:04:24.933
Link: CVE-2026-87737
No data.
OpenCVE Enrichment
Updated: 2026-09-09T11:30:09Z