Skip to main content

Mailcatcher: sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array

0
Medium
Published: 10/03/2026 (10/03/2026, 08:52:56 UTC)
Source: GCVE Database
Product: mailcatcher

Description

A use-after-free vulnerability exists in the sqlite3-ruby gem when defining aggregate functions with two or more arguments evaluated over TEXT or BLOB columns. This can cause the Ruby objects holding arguments to be freed prematurely during garbage collection, leading to incorrect objects being passed to the aggregate's step method or a process crash. The vulnerability affects Mailcatcher versions from 0.8.1 up to but not including 0.11.0. The maintainers rate this as medium severity with a CVSS 4.0 score of 6.3. The issue is fixed in sqlite3 gem version 2.9.6 or later.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

Homebrewmore threats →ghsa
mailcatcher
pkg:brew/mailcatcher
Affected versions
>=0.8.1 <0.11.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:39:03 UTC

Technical Analysis

The vulnerability occurs when using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments. When evaluated over TEXT or BLOB column values, the Ruby objects holding these arguments may be freed during ordinary garbage collection while a later argument is still being converted. This results in the aggregate's step method receiving an incorrect object or the process crashing with a segmentation fault. The defect is triggered without unusual code structuring and can be exploited if an attacker can influence the size of the TEXT or BLOB values. No controlled memory write or denial-of-service exploit has been demonstrated. The issue is resolved by upgrading to sqlite3 gem version 2.9.6 or later.

Potential Impact

An application using vulnerable versions of Mailcatcher that defines multi-argument aggregate functions over TEXT or BLOB columns may experience incorrect values passed to the aggregate's step method or process crashes due to segmentation faults. This can lead to application instability but has not been shown to allow controlled memory corruption or denial-of-service attacks.

Mitigation Recommendations

Upgrade to sqlite3 gem version 2.9.6 or later to resolve the vulnerability. There is no reliable workaround if upgrading is not possible; avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not effective as it only reduces the frequency of the defect but does not prevent it.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-mailcatcher-GHSA-mwm8-39rw-8826
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
4.0

Threat ID: 6ac1398ea43b0b3b89d69986

Added to database: 10/03/2026, 17:21:18 UTC

Last enriched: 10/03/2026, 17:39:03 UTC

Last updated: 10/03/2026, 22:37:36 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses