sqlite3
Ruby bindings for the SQLite3 embedded database
Activity
- Latest release
- 1mo ago
- Total releases
- 85
- Cadence
- ~22 days
- Last 12 months
- 10
Reach
- Downloads
- 191.2M
- Stars
- 843
Details
- License
- BSD-3-Clause
- First release
- Nov 08, 2009
| Version | Released | |
|---|---|---|
2.9.6
patch
| ||
2.9.5
patch
| ||
2.9.4
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.9.3
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.9.2
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.9.2.rc2
pre
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.9.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.9.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.8.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.8.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.7.4
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.7.3
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.7.2
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.7.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.7.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.6.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.5.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.5.0.rc1
pre
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.4.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.4.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.3.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.3.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.1
patch
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.0.rc3
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2026-54620
GHSA-j7fr-3v8c-3qc3
Jul 28, 2026
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid using an aggregate function after closing the database. SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
+ 11 more Show less
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.0.rc2
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.1.0.rc1
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.7.3
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.7.2
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.9
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.8
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.7
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.6
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.5
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.5.rc1
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.4
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.3
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.2
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev |
1.6.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
1.6.1
patch
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev |
1.6.1
patch
Dependencies (6)
Changelog
Compare changes
|
|
1.6.0
minor
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.0.rc2
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev | ||
1.6.0.rc1
pre
1 CVE
CVE-2026-54619
GHSA-28hh-pr2h-2w89
Jul 28, 2026
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
Low
Local
High
Low
None
SummaryUsing MitigationUpgrade to sqlite3 gem v2.9.5 or later. As a workaround, avoid defining multiple custom functions with the same name (varying numbers of arguments or encoding). SeverityThe sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack. Affected versions
0.0.0
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
1.3.10
+ 71 more Show less
1.3.11
1.3.12
1.3.13
1.3.3
1.3.3.beta.1
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.0.rc1
1.5.0.rc2
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.6.0.rc1
1.6.0.rc2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.5.rc1
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.0.rc1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
2.9.2.rc2
2.9.3
2.9.4
Fixed in
2.9.5
References
Updated Jul 28, 2026 · Source: OSV.dev |
1.6.0.rc1
pre
Dependencies (6)
Changelog
Compare changes
|