CVE-2026-89087
CVE-2026-89087 is a high-severity vulnerability with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-573.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- EPSS exploit prediction: 0% (9th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-573
- Published:
- Last modified:
Description
The cstruct package before 6.3.0 for OCaml mishandles indexes.
Frequently asked questions
- What is CVE-2026-89087?
- The cstruct package before 6.3.0 for OCaml mishandles indexes.
- How severe is CVE-2026-89087?
- CVE-2026-89087 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-89087 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (9th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-89087?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-89087 published?
- CVE-2026-89087 was published on 2026-09-10 and last updated on 2026-09-14.
References
Other CWE-573 vulnerabilities
- CVE-2026-41583 — Critical (CVSS 9.1): ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2,…
- CVE-2025-21601 — High (CVSS 7.5): An Improper Following of Specification by Caller vulnerability in web management (J-Web, Captive Portal, 802.1X,…
- CVE-2025-69287 — Medium (CVSS 5.4): The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version…
- CVE-2026-59998 — Medium (CVSS 4.8): sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if…
- CVE-2019-14829 — Medium (CVSS 4.3): A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions…
- CVE-2025-46330 — Low (CVSS 3.3): libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly…