Out-of-Bounds Read Vulnerability in mrubyc by mruby
CVE-2026-38973

4.4MEDIUM

Key Information:

Vendor

mruby

Status
Vendor
CVE Published:
6 July 2026

What is CVE-2026-38973?

A vulnerability has been identified in mrubyc versions up to and including 3.4.1, where an out-of-bounds read occurs during the built-in missing-method lookup process in mrbc_find_method(). This issue can potentially lead to unexpected behavior or unauthorized access to sensitive information within applications using this platform. It is crucial for developers to be aware of this vulnerability and to apply necessary updates to mitigate risks.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.