StackRadar

CVE-2026-54619

Low

Advisory

Published 28 Jul 2026In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 2
affected packages

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
sqlite3gem1.4.1, 1.4.2, 1.4.3, 2.5.0+2 more2.9.515
ruby-sqlite3deb1.4.2-2build1no fix listed1
OSV records
GHSA-28hh-pr2h-2w89UBUNTU-CVE-2026-54619

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
sqlite3@1.4.2
2.9.5

Open the chart page →

4,995
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
sqlite3@1.4.2
2.9.5
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
sqlite3@1.4.2
2.9.5
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
sqlite3@1.4.2
2.9.5
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
sqlite3@1.4.2
2.9.5
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
sqlite3@1.4.2
2.9.5

Open the chart page →

113,791
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
sqlite3@2.5.0
2.9.5

Open the chart page →

7,527
redmineredmine-helm-chartVerified publisher0.2.61 of 1See more

redmine redmine-helm-chart 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
sqlite3@2.5.0
2.9.5

Open the chart page →

4,240
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
sqlite3@2.9.0
2.9.5

Open the chart page →

2,766
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
sqlite3@1.4.3
2.9.5

Open the chart page →

2,814
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
sqlite3@2.8.1
2.9.5

Open the chart page →

1,960
pact-brokerqamatic0.1.01 of 2See more

pact-broker qamatic 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.32.0-2062d6c710099
sqlite3@1.4.1
2.9.5

Open the chart page →

3,533
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
sqlite3@2.5.0
2.9.5

Open the chart page →

4,240
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
sqlite3@1.4.2
2.9.5
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby-sqlite3@1.4.2-2build1
sqlite3@1.4.2
no fix listed
2.9.5

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2026-54619.

Container imageDigestPackageFixed in
wallarm/ingress-ruby:4.2.1-195ea2632326c
sqlite3@1.4.2
2.9.5

Open the chart page →

2,905

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/redmine:6.1.3-trixief474a901faec
sqlite3@2.5.0
2.9.5
2
docuseal/docuseal:2.4.17493fd7f6728
sqlite3@2.9.0
2.9.5
1
library/redmine:6.1.204ac44a2595b
sqlite3@2.5.0
2.9.5
1
pactfoundation/pact-broker:2.32.0-2062d6c710099
sqlite3@1.4.1
2.9.5
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
sqlite3@1.4.2
2.9.5
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
sqlite3@1.4.3
2.9.5
1
wallarm/ingress-ruby:4.2.1-195ea2632326c
sqlite3@1.4.2
2.9.5
1
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
sqlite3@1.4.2
2.9.5
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
ruby-sqlite3@1.4.2-2build1
sqlite3@1.4.2
no fix listed
2.9.5
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
sqlite3@1.4.2
2.9.5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
sqlite3@1.4.2
2.9.5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
sqlite3@1.4.2
2.9.5
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
sqlite3@1.4.2
2.9.5
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
sqlite3@1.4.2
2.9.5
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
sqlite3@2.8.1
2.9.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.