Low severityNVD Advisory· Published Jul 28, 2026· Updated Jul 30, 2026
CVE-2026-54619
CVE-2026-54619
Description
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sqlite3-rubyRubyGems | < 2.9.5 | 2.9.5 |
sqlite3RubyGems | < 2.9.5 | 2.9.5 |
Affected products
1- Range: <=2.9.4
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-28hh-pr2h-2w89ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/sqlite3/CVE-2026-54619.ymlghsaWEB
- github.com/sparklemotion/sqlite3-ruby/commit/2bd436d17f77cdd4c31b00fe9d50b0d21cbaf033nvdWEB
- github.com/sparklemotion/sqlite3-ruby/pull/710nvdWEB
- github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5nvdWEB
- github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-28hh-pr2h-2w89nvdWEB
- www.cve.org/CVERecord/SearchResultsghsaWEB
News mentions
0No linked articles in our index yet.