Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-89086: ocaml/jose may accept forged RSA signatures

CVE-2026-89086 · published 29 days ago
Summary

The OCaml Jose library versions before 0.11.0 can incorrectly mark an RSA signature as valid just because the basic decoding step succeeds, without checking the public key. This could let attackers create signatures that appear authentic. Upgrade to version 0.11.0 or later to ensure proper signature verification.

What to do
  • Update ocaml jose to version 0.11.0 or later.
Affected software
VendorProductAffected versions
ocaml jose < 0.11.0
Original advisory text
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required ...
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-89086 · MITRE
Track software like this
Free during beta