A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.
History

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mruby
Mruby mruby
Vendors & Products Mruby
Mruby mruby

Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in Prism Parser of mruby 4.0.0
Weaknesses CWE-476

Fri, 11 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in Prism Parser of mruby 4.0.0
Weaknesses CWE-476

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in Prism Parser of mruby 4.0.0
Weaknesses CWE-476

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-09-10T00:00:00.000Z

Updated: 2026-09-10T21:49:52.229Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:00.267

Modified: 2026-09-10T22:17:00.267

Link: CVE-2026-79590

cve-icon Redhat

No data.