CVE Tools

Mruby

47 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mruby, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Mruby CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mruby CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-112
2025-121
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1736%
  • High2043%
  • Medium919%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mruby.

  1. CVE-2026-1979mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free5.3
  2. CVE-2025-61594URI Credential Leakage Bypass over CVE-2025-272217.5
  3. CVE-2025-13120mruby array.c sort_cmp use after free5.3
  4. CVE-2025-12875mruby array.c ary_fill_exec out-of-bounds write5.3
  5. CVE-2025-7207mruby nregs codegen.c scope_new heap-based overflow3.3
  6. CVE-2023-28755A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time...5.3
  7. CVE-2021-46023An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.7.5
  8. CVE-2021-33621The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an ...8.8
  9. CVE-2022-1934Use After Free in mruby/mruby7.8
  10. CVE-2022-1427Out-of-bounds Read in mrb_obj_is_kind_of in in mruby/mruby7.8
  11. CVE-2022-1286heap-buffer-overflow in mrb_vm_exec in mruby/mruby in mruby/mruby9.8
  12. CVE-2022-1276Out-of-bounds Read in mrb_get_args in mruby/mruby9.8
  13. CVE-2022-1212Use-After-Free in str_escape in mruby/mruby in mruby/mruby9.8
  14. CVE-2022-1201NULL Pointer Dereference in mrb_vm_exec with super in mruby/mruby6.5
  15. CVE-2022-1106use after free in mrb_vm_exec in mruby/mruby9.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store