<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:33:28.555628+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365533</id>
    <title>EUVD-2026-365533</title>
    <updated>2026-10-03T09:33:28.638167+00:00</updated>
    <content>EUVD-2026-365533</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87733</id>
    <title>fkie_cve-2026-87733</title>
    <updated>2026-10-03T09:33:28.638203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-87733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5v5p-5xxr-9xf8</id>
    <title>GHSA-5v5p-5xxr-9xf8</title>
    <updated>2026-10-03T09:33:28.638235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5v5p-5xxr-9xf8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/osec-2026-13</id>
    <title>OSEC-2026-13 — ECDSA accepts the point at infinity as a P256, P384, P521 public key</title>
    <updated>2026-10-03T09:33:28.638252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> opam: mirage-crypto-ec</p>
<p>`P256{,P384,P521}.Dsa.pub_of_octets` accepts 0x00, the encoding of the point at infinity, as a public key. The Diffie-Hellman path rejects that point (`point_of_octets`); the ECDSA path skips the same check. Under such a key a signature can be forged with no private key, as the repro shows.</p>
<p>The same class is treated as high severity elsewhere. CVE-2022-21449 ("Psychic Signatures", OpenJDK) let a blank ECDSA signature verify, and CVE-2020-0601 ("CurveBall", Windows CryptoAPI) accepted a crafted ECC public key for certificate validation. Both are missing-validation forgeries on the same primitive.</p>
<p>## Solution</p>
<p>Check for point at infinity in `pub_of_octets`.</p>
<p>## Reproduction</p>
<p>```OCaml
module Dsa = Mirage_crypto_ec.P256.Dsa</p>
<p>(* 0x00 is the SEC1 encoding of the point at infinity A a signature using it can be forged for
   any message with no private key. *)
let () =
  Mirage_crypto_rng.(set_default_generator (create ~seed:"forge" (module Fortuna)));
  let o_key = Result.get_ok (Dsa.pub_of_octets "\x00") in
  let z = Digestif.SHA256.(to_raw_string (digest_string "transfer 1000eur to mallory")) in
  let r, _ = Dsa.sign ~key:(Result.get_ok (Dsa.priv_of_octets z)) ~k:z z in
  let s = String.make 31 '\000' ^ "\001" in
  Printf.printf "0x00 accepted as a public key:    %b\n" (Result.is_ok (Dsa.pub_of_octets "\x00"));
  Printf.printf "forged (r, s=1) verifies under O:  %b\n" (Dsa.verify ~key:o_key (r, s) z)
```</p>
<p>## Timeline</p>
<p>- June 25th 2026: report to ocaml/security-advisories
- June…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/osec-2026-13"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87733</id>
    <title>UBUNTU-CVE-2026-87733</title>
    <updated>2026-10-03T09:33:28.638298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: ocaml-mirage-crypto, Ubuntu:24.04:LTS: ocaml-mirage-crypto, Ubuntu:26.04:LTS: ocaml-mirage-crypto</p>
<p>An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87733"/>
  </entry>
</feed>
