CVE-2026-54620
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.
| CWE | CWE-416 |
| Vendor | sparklemotion |
| Product | sqlite3-ruby |
| Published | Jul 28, 2026 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for sparklemotion sqlite3-ruby
Be the first to know when new unknown vulnerabilities affecting sparklemotion sqlite3-ruby are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sparklemotion / sqlite3-ruby
>= 2.1.0, < 2.9.5
References
github.com: https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3 github.com: https://github.com/sparklemotion/sqlite3-ruby/pull/711 github.com: https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726 github.com: https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5