CVE-2026-86547
MEDIUM
NVD
CVSS Score
6.2
Severity
MEDIUM
Published
Sep 09, 2026
Vendor
unknown
Description
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.