CVE-2026-86547: Mrubyc

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.

Affected products

  • Mrubyc Mrubyc: from 2.0, up to and including 4.0.0

Published 2026-09-09. Last modified 2026-09-10.