VYPR
Medium severity6.2NVD Advisory· Published Sep 9, 2026

CVE-2026-86547

CVE-2026-86547

Description

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Mrubyc/Mrubycllm-fuzzy2 versions
    <=4.0.0+ 1 more
    • (no CPE)range: <=4.0.0
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.