Mailcatcher: sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
A use-after-free vulnerability exists in the sqlite3-ruby gem when defining aggregate functions with two or more arguments evaluated over TEXT or BLOB columns. This can cause the Ruby objects holding arguments to be freed prematurely during garbage collection, leading to incorrect objects being passed to the aggregate's step method or a process crash. The vulnerability affects Mailcatcher versions from 0.8.1 up to but not including 0.11.0. The maintainers rate this as medium severity with a CVSS 4.0 score of 6.3. The issue is fixed in sqlite3 gem version 2.9.6 or later.
AI Analysis
Technical Summary
The vulnerability occurs when using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments. When evaluated over TEXT or BLOB column values, the Ruby objects holding these arguments may be freed during ordinary garbage collection while a later argument is still being converted. This results in the aggregate's step method receiving an incorrect object or the process crashing with a segmentation fault. The defect is triggered without unusual code structuring and can be exploited if an attacker can influence the size of the TEXT or BLOB values. No controlled memory write or denial-of-service exploit has been demonstrated. The issue is resolved by upgrading to sqlite3 gem version 2.9.6 or later.
Potential Impact
An application using vulnerable versions of Mailcatcher that defines multi-argument aggregate functions over TEXT or BLOB columns may experience incorrect values passed to the aggregate's step method or process crashes due to segmentation faults. This can lead to application instability but has not been shown to allow controlled memory corruption or denial-of-service attacks.
Mitigation Recommendations
Upgrade to sqlite3 gem version 2.9.6 or later to resolve the vulnerability. There is no reliable workaround if upgrading is not possible; avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not effective as it only reduces the frequency of the defect but does not prevent it.
Mailcatcher: sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
Description
A use-after-free vulnerability exists in the sqlite3-ruby gem when defining aggregate functions with two or more arguments evaluated over TEXT or BLOB columns. This can cause the Ruby objects holding arguments to be freed prematurely during garbage collection, leading to incorrect objects being passed to the aggregate's step method or a process crash. The vulnerability affects Mailcatcher versions from 0.8.1 up to but not including 0.11.0. The maintainers rate this as medium severity with a CVSS 4.0 score of 6.3. The issue is fixed in sqlite3 gem version 2.9.6 or later.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability occurs when using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments. When evaluated over TEXT or BLOB column values, the Ruby objects holding these arguments may be freed during ordinary garbage collection while a later argument is still being converted. This results in the aggregate's step method receiving an incorrect object or the process crashing with a segmentation fault. The defect is triggered without unusual code structuring and can be exploited if an attacker can influence the size of the TEXT or BLOB values. No controlled memory write or denial-of-service exploit has been demonstrated. The issue is resolved by upgrading to sqlite3 gem version 2.9.6 or later.
Potential Impact
An application using vulnerable versions of Mailcatcher that defines multi-argument aggregate functions over TEXT or BLOB columns may experience incorrect values passed to the aggregate's step method or process crashes due to segmentation faults. This can lead to application instability but has not been shown to allow controlled memory corruption or denial-of-service attacks.
Mitigation Recommendations
Upgrade to sqlite3 gem version 2.9.6 or later to resolve the vulnerability. There is no reliable workaround if upgrading is not possible; avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not effective as it only reduces the frequency of the defect but does not prevent it.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-mailcatcher-GHSA-mwm8-39rw-8826
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac1398ea43b0b3b89d69986
Added to database: 10/03/2026, 17:21:18 UTC
Last enriched: 10/03/2026, 17:39:03 UTC
Last updated: 10/03/2026, 22:37:36 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.