Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-82481: OCaml cohttp package lets attackers access files outside intended folder

CVE-2026-82481 · published 5 days ago
Summary

The cohttp library used in OCaml applications can be tricked into reading or writing files outside the designated directory, which could expose sensitive data or allow unauthorized changes. Upgrade to version 6.3.0 or later, or apply the available patches, and review any code that relies on this library to ensure proper file handling.

What to do
  • Update mirage cohttp to version 6.3.0 or later.
Affected software
Ecosystem VendorProductAffected versions
– mirage cohttp < 6.3.0
Debian:12 debian ocaml-cohttp All versions
Debian:13 debian ocaml-cohttp All versions
Debian:14 debian ocaml-cohttp All versions
Original advisory text
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
Severity
8.7 High
CVSS 4.0: 8.3 (OSV)
Exploitation
EPSS <1%
Type
CWE-180Incorrect Behavior Order: Validate Before Canonicalize
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82481 · MITRE
Monitor software like this
Free during beta