Wren's vulnerability footprint centers on a single focused product and clusters around memory-safety and resource-handling weaknesses, including buffer overflows, out-of-bounds reads, NULL pointer dereferences, and improper resource cleanup. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wren over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3386HIGH A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bound | Mar 1, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-2858HIGH A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipu | Feb 20, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-3385MEDIUM A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recur | Mar 1, 2026 | 5.5 | 21 | NO | NO |
CVE-2026-2657MEDIUM A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such m | Feb 18, 2026 | 5.5 | 20 | NO | NO |
CVE-2026-3387MEDIUM A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation | Mar 1, 2026 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wren.
Media articles that mention a CVE ID that affects a product developed by Wren — matched by CVE ID, not by vendor name.