
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-51294 is a rejected CVE record that was originally described as a use-after-free (UAF) vulnerability in SQLite 3.41's jsonArrayLengthFunc function (located in src/json.c). The CVE was published on July 30, 2026, but was subsequently withdrawn by its CNA (MITRE) after further investigation determined it was not a security issue (Github Advisory, Feedly). The record carries the official status of "Rejected" with the note: "DO NOT USE THIS CVE RECORD." No valid CVSS score applies to this rejected entry; the ENISA record lists a base score of 0.0, and the EPSS score is approximately 0.145% (Github Advisory). Notably, reporting from CTI Pilot (August 4, 2026) linked this and related SQLite advisories to LLM-fabricated CVEs that were subsequently withdrawn by BSI and NCSC-NL.
The original (now-rejected) advisory claimed a CWE-416 (Use After Free) flaw in jsonArrayLengthFunc within SQLite's src/json.c. The alleged root cause was an improper memory lifecycle ordering: jsonParseFree(p) was said to fully deallocate a JsonParse heap structure, after which the dangling pointer p was purportedly dereferenced again in countJsonArrayItems(p, ...) without being nulled (programmervuln advisory). However, because this CVE has been officially rejected as not a security issue, these technical claims should not be treated as verified or accurate. The advisory originated from a repository (programmervuln/cveadvisory-) associated with fabricated vulnerability reports, and no independent technical confirmation of the described code path exists.
Because CVE-2026-51294 has been officially rejected and determined not to be a security issue, there is no confirmed security impact. The original (unverified) advisory claimed potential denial of service via process crash and limited information disclosure through out-of-bounds reads on reclaimed heap memory, but these claims were not substantiated and the CVE was withdrawn by its CNA (Github Advisory).
CVE-2026-51294 is a rejected CVE with no confirmed exploitability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no evidence of any public proof-of-concept or in-the-wild exploitation (Feedly). The EPSS score is approximately 0.145% (4th percentile), reflecting a very low probability of exploitation. CTI Pilot reporting from August 4, 2026 indicates this CVE was among a set of SQLite advisories identified as LLM-fabricated and subsequently withdrawn by national cybersecurity agencies including BSI and NCSC-NL.
No mitigation is required, as CVE-2026-51294 has been officially rejected and is not a valid security vulnerability. Organizations should disregard any advisories or alerts referencing this CVE ID. If automated vulnerability scanners flag this CVE, the finding should be marked as a false positive based on the official rejection status (Github Advisory).
CTI Pilot reported on August 4, 2026 that BSI and NCSC-NL withdrew SQLite-related advisories — including this CVE — after determining they were fabricated by large language models (LLMs) rather than discovered through legitimate security research. This incident highlights growing concerns in the security community about AI-generated vulnerability reports polluting CVE databases and consuming analyst resources. The programmervuln/cveadvisory- GitHub repository, which served as the primary reference for this CVE, has been identified as a source of fabricated advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."