Skip to main content
Security

Critical CVE issued for hallucinated SQLite vulnerability

JFrog security researchers said Monday they found that a batch of critical SQLite vulnerability advisories published to GitHub and flagged by the National Vulnerability Database and CISA were fabricated. The advisories originated from a newly created GitHub repository, programmervuln/cveadvisory-, which published more than 50 CVEs. NVD initially flagged the SQLite entries as critical and CISA's Authorized Data Publisher agreed. JFrog researchers verified the claims by cloning the official SQLite repository, building isolated Docker containers and testing proof-of-concept payloads under AddressSanitizer instrumentation. They found cited functions did not exist in the targeted versions, referenced line numbers were incorrect and proof-of-concept queries either failed at the parser stage or executed without errors. One advisory claimed a heap use-after-free in sqlite3ReleaseTempReg, but the function recycles register indices and does not deallocate memory. Another cited a function, exprComputeOperands, that was added in mid-2025, months after the targeted SQLite 3.41.0 release. Red Hat initially assigned CVE-2026-51302 a 10.0 Critical severity score before downgrading it to 7.6 High. A broader audit of 55 advisories from the same GitHub account revealed 54 were completely fabricated. JFrog said the CVE submission process via MITRE's public form lacks identity verification and that NIST paused deep analysis in February 2024 due to a surge in reports.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from research.jfrog.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

Port of Los Angeles reports 120 million cyberattack attempts

The Port of Los Angeles foiled more than 120 million cyberattack attempts in August, according to Bloomberg. The U.S.'s busiest container port for global trade faces a persistent operational threat while navigating shifting tariff...

Security
Security

Cisco warns of actively exploited ISE authentication bypass

Cisco warned that CVE-2026-76460, a maximum-severity flaw in Identity Services Engine and ISE Passive Identity Connector, is being actively exploited. The reported API authentication-control weakness can let an unauthenticated rem...

Capital Security
Capital Security

Comp AI raises $34 million Series A for compliance platform

Cybersecurity and compliance startup Comp AI has raised a $34 million Series A led by Roo Capital and Grand Ventures. The company says its platform uses AI agents to draft security policies, collect audit evidence and continuousl...

Capital Robotics
Capital Robotics

Treble raises €15 million for acoustic AI simulation

Reykjavík-based Treble raised approximately €15 million in a Series A-2 round led by Paladin Capital Group, bringing its total funding to €36 million. Treble's cloud platform models sound in physical spaces to create synthetic aud...

Science
Science

Phase-one mesothelioma study reports PRX3 inhibitor results

Researchers at the University of Vermont and collaborators reported phase-one results for RSO-021, a clinical formulation of thiostrepton, in relapsed mesothelioma. In 15 patients, the trial controlled disease progression in 67%;...

Robotics Science
Robotics Science

MIT demonstrates reconfigurable robotic optics lab

MIT researchers demonstrated a reconfigurable robotic optics lab that autonomously assembled and tuned a tabletop laser cavity. The seven-jointed arm picked, placed and adjusted optical components, completing 50 maneuvers within 3...