CVE-2026-86547 mrubyc through 4.0.0 contains a null pointer… — CVE Notify — TG.ME

🚨 CVE-2026-86547
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.

🎖@cveNotify
GitHub
mrubyc/src/vm.c at 4261cf5e5ae5579e3110dab98a04b91c7d919429 · mrubyc/mrubyc
mruby/c is another implementation of mruby. Contribute to mrubyc/mrubyc development by creating an account on GitHub.
September 9, 2026 21