Back to CVE List

CVE-2026-54620

LOW SEVERITY

Vulnerability Description

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-416
Source
NVD
Vendor
sparklemotion
Product
sqlite3-ruby

External References

Discussion (0)

Add Comment

No comments yet. Be the first!