Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mruby

First CVE: Jun 11, 2017Active for: 9 yearsTotal CVEs: 42
47.8
VTI Score
High

Mruby is a lightweight, embeddable Ruby interpreter designed for resource-constrained environments and integration into larger applications, and despite a narrow product scope, sits prominently in the vulnerability landscape due to its widespread adoption across embedded systems, IoT devices, and third-party software. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety challenges inherent to a C-based interpreter implementation that processes untrusted script input. The exposure recurs consistently through memory-management weakness classes including NULL-pointer dereferences, use-after-free conditions, buffer overflows, and out-of-bounds access—flaws that can compromise the integrity of host applications or enable arbitrary code execution from within the interpreter sandbox. Defenders should monitor mruby updates closely and prioritize patching in internet-facing or privilege-sensitive deployments, particularly where the interpreter processes untrusted input; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mruby over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2017
9 years ago
Most Recent CVE
Feb 6, 2026
168 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-1286CRITICAL
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Apr 10, 20229.831NONO
CVE-2022-0570CRITICAL
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
Feb 14, 20229.831NONO
CVE-2018-11743CRITICAL
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialize
Jun 5, 20189.831NONO
CVE-2018-10199CRITICAL
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can poss
Apr 18, 20189.831NONO
CVE-2018-10191CRITICAL
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in
Apr 17, 20189.831NONO
CVE-2022-1276CRITICAL
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Apr 10, 20229.830NONO
CVE-2020-15866CRITICAL
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy
Jul 21, 20209.830NONO
CVE-2022-0631CRITICAL
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
Feb 18, 20229.829NONO
CVE-2022-0525CRITICAL
Out-of-bounds Read in Homebrew mruby prior to 3.2.
Feb 9, 20229.128NONO
CVE-2022-1212CRITICAL
Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Apr 5, 20229.827NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
19%
40%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local15 (35.7%)
Network27 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None34 (81.0%)
Unknown0 (0.0%)
Required8 (19.0%)
Privileges Required
Low8 (19.0%)
High0 (0.0%)
None34 (81.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mruby.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mruby — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mruby's Products

View all 3 CNAs →

Top CWEs