Review reviewHigh
CVE-2026-38976
the affected product
mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.
- CVSS
- 7.5
- EPSS
- 0.45% 36.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07