A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 22:17
Updated : 2026-09-14 18:20
NVD link : CVE-2026-79590
Mitre link : CVE-2026-79590
CVE.ORG link : CVE-2026-79590
JSON object : View
Products Affected
No product.
CWE
CWE-476
NULL Pointer Dereference
