CVE-2022-4996CWE-1077

CVE-2022-4996

Medium · published August 20, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
40.0
In the wild
Unconfirmed
What it is

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00485 · 40.0th percentile
Weakness
CWE-1077 · Floating Point Comparison with Incorrect Operator
Published
2026-08-20T04:16Z
References (5)
EPSS history
Timeline
  • 19 AUG 23:45Z
    mruby bigint.c udiv floating point comparison with incorrect operator
    cvelistv5