cbcvebase.

Ghost Sqlite3 vulnerabilities

64 known vulnerabilities affecting ghost/sqlite3.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH32MEDIUM21LOW2

Vulnerabilities

Page 4 of 4
CVE-2025-29088P4MEDIUMCVSS 5.5≥ 0, < 3.46.1-42025-04-10
CVE-2025-29088 [MEDIUM] CVE-2025-29088: In SQLite 3 In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
osv
CVE-2026-54619P4LOW≥ 0, < 2.9.52026-07-28
CVE-2026-54619 [LOW] CWE-416 sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity ## Summary Using `Database#create_function` or `Database#define_function` to define the same function name more than once with different numbers of arguments ("arity") or text encodings will result in a invalid memory read and a segmentation fault. ## Mitigation Upgrade to sqlite3 gem v2.9.5 or
ghsa
CVE-2026-54620P4LOW≥ 2.1.0, < 2.9.52026-07-28
CVE-2026-54620 [LOW] CWE-416 sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks ## Summary Using `Database#create_aggregate`, `#create_aggregate_handler`, or `Database#define_aggregator` to define an aggregate function, and then using an open statement calling that function after the database has been explicitly closed will result in an invalid memory read and a segmentation fault. ## Mitigation Upgrad
ghsa
CVE-2025-52099MEDIUMCVSS 5.5≥ 0, < 3.46.1-42025-10-24
CVE-2025-52099 [MEDIUM] CVE-2025-52099: Integer Overflow vulnerability in SQLite SQLite3 v Integer Overflow vulnerability in SQLite SQLite3 v.3.50.0 allows a remote attacker to cause a denial of service via the setupLookaside function
osv
Ghost Sqlite3 vulnerabilities | cvebase