CVE-2026-38973: Medium severity mruby mruby/c vulnerability
Published Jul 6, 2026
·Updated
mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbcfindmethod().
Affected Software
1 affected component
mruby mruby/c<=3.4.1
Event History
Jul 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-38973?
The severity of CVE-2026-38973 is medium with a CVSS score of 4.4.
2
What are the risks associated with CVE-2026-38973?
CVE-2026-38973 presents a risk of out-of-bounds read within mruby, which could lead to information disclosure.
3
How do I fix CVE-2026-38973?
To fix CVE-2026-38973, upgrade to a version of mruby released after 3.4.1 that addresses the vulnerability.
4
Which versions of mruby are affected by CVE-2026-38973?
CVE-2026-38973 affects mruby versions before 3.4.1.
5
What software is impacted by CVE-2026-38973?
CVE-2026-38973 impacts the mruby/c software.