Windowsforum OCaml Vulnerability CVE-2026-28364 Allows Remote Code Execution
Article Content
Browse articles
A vulnerability tracked as CVE-2026-28364 affects OCaml versions prior to 4.14.3 and 5.x before 5.4.1, enabling remote code execution through a multi-phase attack chain. This issue arises from a buffer over-read in the Marshal deserialization process due to missing bounds validation in the readblock() function. Patches have been released to address this vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
Timeline
2026-02-27
CVE-2026-28364 published
2026-02-28
Patches 4.14.3 and 5.4.1 released to block RCE
2026-02-28
Articles published detailing the vulnerability
More articles in this cluster (2)
Following this threat?
Track CVE-2026-28364 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Vulnerabilities in OCaml Libraries Affecting Fedora 45 A mass rebuild of the OCaml ecosystem for Fedora 45 has addressed multiple vulnerabilities, including CVE-2026-28364, which allows remote code execution via buffer over-read in Marshal deserialization. This vulnerability affects various OCaml libraries, including ocaml-stdcompat, ocaml-uuseg, and others. The issues…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…