CVE-2026-54619: Sparklemotion SQLITE3-Ruby
Low severity, CVSS 2.0. EPSS: 0.1% chance of exploitation in the next 30 days.
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5.
Affected products
- Sparklemotion SQLITE3-Ruby: before 2.9.5 (fixed in 2.9.5)
Published 2026-07-28. Last modified 2026-07-30.