CVE-2026-38976

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.

Published 2026-07-06. Last modified 2026-07-07.