CVE-2026-54620

LOW

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

Title source: cna
STIX 2.1

Description

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

Scores

CVSS v4 2.0
EPSS 0.0011
EPSS Percentile 1.3%
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (3)
rubygems/sqlite3 2.1.0 - 2.9.5RubyGems
rubygems/sqlite3-ruby 2.1.0 - 2.9.5RubyGems
sparklemotion/sqlite3-ruby >= 2.1.0, < 2.9.5
Published Jul 28, 2026
Tracked Since Jul 28, 2026