Loading market data...
← Back to CVE feed

CVE-2026-54620

UNKNOWN View on NVD ↗

Description

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

Published: Jul 28, 2026 17:16 UTC Modified: Jul 28, 2026 18:17 UTC