CVE-2026-54620
LowAdvisory
Published 28 Jul 2026In the index since 8 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 2.0
- base score, highest
- EPSS
- 0.001
- 1st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| sqlite3gem | 2.5.0, 2.8.1, 2.9.0 | 2.9.5 | 4 |
| ruby-sqlite3deb | 1.4.2-2build1 | no fix listed | 1 |
- OSV records
- GHSA-j7fr-3v8c-3qc3UBUNTU-CVE-2026-54620
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| redminemt190502 | 7.3.4 | 1 of 3See more | 7,527 |
| redmineredmine-helm-chartVerified publisher | 0.2.6 | 1 of 1See more | 4,240 |
| antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher | 0.2.0 | 1 of 1See more | 2,766 |
| manyfoldjeffrescVerified publisher | 1.0.3 | 1 of 1See more | 1,960 |
| redminerestic-pvc-backupVerified publisher | 0.2.6 | 1 of 1See more | 4,240 |
| kongwallarmVerified publisher | 4.6.3 | 1 of 7See more | 11,405 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | f474a901faec | sqlite3 | 2.9.5 | 2 |
| docuseal/ | 7493fd7f6728 | sqlite3 | 2.9.5 | 1 |
| library/ | 04ac44a2595b | sqlite3 | 2.9.5 | 1 |
| wallarm/ | ea9608c82e40 | ruby-sqlite3 | no fix listed | 1 |
| ghcr.io/ | d14ca4d82475 | sqlite3 | 2.9.5 | 1 |