Skip to content

CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker

Api.Msrc.Microsoft • February 28, 2026

Information published.

Extracted Entities

Attack Types (1)

Platforms (1)