CVE-2020-36401: Mruby

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

Affected products

  • Mruby Mruby: version 2.1.2 only

Published 2021-07-01. Last modified 2026-06-17.