Known Vulnerabilities for products from Mruby

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mruby".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-1979 json A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNO... Not Provided 2026-02-06 2026-04-29
CVE-2025-13120 json A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c... Not Provided 2025-11-13 2026-04-29
CVE-2025-12875 json A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mrub... Not Provided 2025-11-07 2026-04-29
CVE-2025-7207 json A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new ... Not Provided 2025-07-09 2026-04-29
CVE-2022-1934 json Use After Free in GitHub repository mruby/mruby prior to 3.2. 7.8 - HIGH 2022-05-31 2022-06-08
CVE-2022-1427 json Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code ... 7.8 - HIGH 2022-04-23 2023-01-17
CVE-2022-1286 json heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code exe... 9.8 - CRITICAL 2022-04-10 2022-04-18
CVE-2022-1276 json Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being ... 9.8 - CRITICAL 2022-04-10 2022-04-15
CVE-2022-1212 json Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution ... 9.8 - CRITICAL 2022-04-05 2022-04-12
CVE-2022-1201 json NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capab... 6.5 - MEDIUM 2022-04-02 2023-01-17
CVE-2022-1106 json use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. 9.1 - CRITICAL 2022-03-27 2022-03-31
CVE-2022-1071 json User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. 8.2 - HIGH 2022-03-26 2022-03-31
CVE-2022-0890 json NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2. 5.5 - MEDIUM 2022-03-10 2022-03-17
CVE-2022-0717 json Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. 9.1 - CRITICAL 2022-02-23 2022-03-02
CVE-2022-0632 json NULL Pointer Dereference in Homebrew mruby prior to 3.2. 5.5 - MEDIUM 2022-02-19 2022-02-28
CVE-2022-0631 json Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. 9.8 - CRITICAL 2022-02-18 2022-02-25
CVE-2022-0630 json Out-of-bounds Read in Homebrew mruby prior to 3.2. 7.1 - HIGH 2022-02-19 2022-02-28
CVE-2022-0623 json Out-of-bounds Read in Homebrew mruby prior to 3.2. 9.1 - CRITICAL 2022-02-17 2022-02-24
CVE-2022-0614 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.5 - MEDIUM 2022-02-16 2023-01-17
CVE-2022-0570 json Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. 9.8 - CRITICAL 2022-02-14 2022-02-22

Known software with vulnerabilities from Mruby

Type Vendor Product Version
ApplicationMrubyMruby1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report