CVE-2026-86547

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 10:22

Updated : 2026-09-10 19:58


NVD link : CVE-2026-86547

Mitre link : CVE-2026-86547

CVE.ORG link : CVE-2026-86547


JSON object : View

Products Affected

No product.

CWE
CWE-476

NULL Pointer Dereference