CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

08 Jul 2026, 03:29

Type Values Removed Values Added
References () https://github.com/ocaml/opam/pull/6897 - () https://github.com/ocaml/opam/pull/6897 - Issue Tracking, Patch
References () https://github.com/ocaml/opam/releases/tag/2.5.1 - () https://github.com/ocaml/opam/releases/tag/2.5.1 - Release Notes
References () https://osv.dev/vulnerability/OSEC-2026-03 - () https://osv.dev/vulnerability/OSEC-2026-03 - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html - () https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html - Mailing List, Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2026-41082 - () https://access.redhat.com/security/cve/CVE-2026-41082 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2459003 - () https://bugzilla.redhat.com/show_bug.cgi?id=2459003 - Issue Tracking
References () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json - () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json - Third Party Advisory
First Time Debian
Debian debian Linux
Redhat enterprise Linux
Redhat
Ocaml
Ocaml opam
CPE cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
CWE CWE-22

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-41082 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2459003 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json -

16 Jun 2026, 17:16

Type Values Removed Values Added
References () https://osv.dev/vulnerability/OSEC-2026-03 - () https://osv.dev/vulnerability/OSEC-2026-03 -

15 Jun 2026, 20:16

Type Values Removed Values Added
References
  • () https://osv.dev/vulnerability/OSEC-2026-03 -

21 Apr 2026, 10:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html -

16 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-16 18:16

Updated : 2026-07-15 02:21


NVD link : CVE-2026-41082

Mitre link : CVE-2026-41082

CVE.ORG link : CVE-2026-41082


JSON object : View

Products Affected

ocaml

  • opam

debian

  • debian_linux

redhat

  • enterprise_linux
CWE
CWE-24

Path Traversal: '../filedir'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')