Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-82481: OCaml cohttp package lets attackers access files outside intended folder
CVE-2026-82481 · published 5 days ago
Summary
The cohttp library used in OCaml applications can be tricked into reading or writing files outside the designated directory, which could expose sensitive data or allow unauthorized changes. Upgrade to version 6.3.0 or later, or apply the available patches, and review any code that relies on this library to ensure proper file handling.
What to do
- Update mirage cohttp to version 6.3.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | mirage | cohttp | < 6.3.0 |
| Debian:12 | debian | ocaml-cohttp | All versions |
| Debian:13 | debian | ocaml-cohttp | All versions |
| Debian:14 | debian | ocaml-cohttp | All versions |
Original advisory text
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
References
Severity
8.7
High
CVSS 4.0: 8.3 (OSV)
Exploitation
EPSS <1%
Type
CWE-180Incorrect Behavior Order: Validate Before Canonicalize
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta