📦 Mruby

by Mruby

🔍 What is Mruby?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-1276

CRITICAL CVSS 9.8 Apr 10, 2022

CVE-2022-1276 is an out-of-bounds read vulnerability in mruby's mrb_get_args function that could allow attackers to read sensitive memory contents. If exploited, this could lead to arbitrary code exec...

CVE-2022-1212

CRITICAL CVSS 9.8 Apr 5, 2022

CVE-2022-1212 is a use-after-free vulnerability in mruby's str_escape function that could allow attackers to execute arbitrary code. This affects applications using mruby versions prior to 3.2. The vu...

CVE-2022-1106

CRITICAL CVSS 9.1 Mar 27, 2022

CVE-2022-1106 is a use-after-free vulnerability in mrb_vm_exec in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to execute arbitrary code or cause denial of service by ...

CVE-2022-0717

CRITICAL CVSS 9.1 Feb 23, 2022

CVE-2022-0717 is an out-of-bounds read vulnerability in mruby, a lightweight implementation of the Ruby programming language. This vulnerability could allow attackers to read sensitive memory contents...

CVE-2022-0631

CRITICAL CVSS 9.8 Feb 18, 2022

CVE-2022-0631 is a heap-based buffer overflow vulnerability in mruby (a lightweight Ruby implementation) that allows attackers to execute arbitrary code or cause denial of service. It affects systems ...

CVE-2022-0623

CRITICAL CVSS 9.1 Feb 17, 2022

CVE-2022-0623 is an out-of-bounds read vulnerability in mruby (a lightweight Ruby implementation) that could allow attackers to read sensitive memory contents. This affects systems running mruby versi...

CVE-2022-0080

CRITICAL CVSS 9.8 Jan 2, 2022

CVE-2022-0080 is a heap-based buffer overflow vulnerability in mruby, a lightweight implementation of the Ruby programming language. Attackers can exploit this to execute arbitrary code or cause denia...

CVE-2022-1427

HIGH CVSS 7.8 Apr 23, 2022

CVE-2022-1427 is an out-of-bounds read vulnerability in mrb_obj_is_kind_of function in mruby, a lightweight Ruby implementation. This could allow attackers to read sensitive memory contents and potent...

CVE-2022-1071

HIGH CVSS 8.2 Mar 26, 2022

CVE-2022-1071 is a use-after-free vulnerability in mrb_vm_exec in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to execute arbitrary code or cause denial of service by ...

CVE-2022-0630

HIGH CVSS 7.1 Feb 19, 2022

CVE-2022-0630 is an out-of-bounds read vulnerability in mruby, a lightweight Ruby implementation. This vulnerability allows attackers to read memory beyond allocated buffers, potentially exposing sens...

CVE-2022-0481

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-0481 is a NULL pointer dereference vulnerability in mruby (a lightweight Ruby implementation) that can cause denial of service or potentially arbitrary code execution when processing maliciou...

CVE-2021-46020

HIGH CVSS 7.5 Jan 14, 2022

This vulnerability involves an untrusted pointer dereference in mruby's virtual machine execution function, which can cause a segmentation fault and crash the application. It affects systems running m...

CVE-2021-4110

HIGH CVSS 7.5 Dec 15, 2021

CVE-2021-4110 is a NULL pointer dereference vulnerability in mruby, a lightweight implementation of the Ruby programming language. This vulnerability allows attackers to cause denial of service (DoS) ...

CVE-2026-1979

MEDIUM CVSS 5.3 Feb 6, 2026

A use-after-free vulnerability in mruby up to version 3.4.0 allows local attackers to execute arbitrary code or cause denial of service. This affects the JMPNOT-to-JMPIF optimization in the virtual ma...

CVE-2025-13120

MEDIUM CVSS 5.3 Nov 13, 2025

This CVE describes a use-after-free vulnerability in mruby's sort_cmp function that could allow local attackers to execute arbitrary code or cause denial of service. The vulnerability affects mruby ve...

CVE-2025-12875

MEDIUM CVSS 5.3 Nov 7, 2025

This CVE describes an out-of-bounds write vulnerability in mruby 3.4.0's array handling function. Attackers with local access can manipulate arguments to cause memory corruption, potentially leading t...