CVE-2026-51294
SQLite vulnerability analysis and mitigation

Overview

CVE-2026-51294 is a rejected CVE record that was originally described as a use-after-free (UAF) vulnerability in SQLite 3.41's jsonArrayLengthFunc function (located in src/json.c). The CVE was published on July 30, 2026, but was subsequently withdrawn by its CNA (MITRE) after further investigation determined it was not a security issue (Github Advisory, Feedly). The record carries the official status of "Rejected" with the note: "DO NOT USE THIS CVE RECORD." No valid CVSS score applies to this rejected entry; the ENISA record lists a base score of 0.0, and the EPSS score is approximately 0.145% (Github Advisory). Notably, reporting from CTI Pilot (August 4, 2026) linked this and related SQLite advisories to LLM-fabricated CVEs that were subsequently withdrawn by BSI and NCSC-NL.

Technical details

The original (now-rejected) advisory claimed a CWE-416 (Use After Free) flaw in jsonArrayLengthFunc within SQLite's src/json.c. The alleged root cause was an improper memory lifecycle ordering: jsonParseFree(p) was said to fully deallocate a JsonParse heap structure, after which the dangling pointer p was purportedly dereferenced again in countJsonArrayItems(p, ...) without being nulled (programmervuln advisory). However, because this CVE has been officially rejected as not a security issue, these technical claims should not be treated as verified or accurate. The advisory originated from a repository (programmervuln/cveadvisory-) associated with fabricated vulnerability reports, and no independent technical confirmation of the described code path exists.

Impact

Because CVE-2026-51294 has been officially rejected and determined not to be a security issue, there is no confirmed security impact. The original (unverified) advisory claimed potential denial of service via process crash and limited information disclosure through out-of-bounds reads on reclaimed heap memory, but these claims were not substantiated and the CVE was withdrawn by its CNA (Github Advisory).

Exploitability

CVE-2026-51294 is a rejected CVE with no confirmed exploitability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no evidence of any public proof-of-concept or in-the-wild exploitation (Feedly). The EPSS score is approximately 0.145% (4th percentile), reflecting a very low probability of exploitation. CTI Pilot reporting from August 4, 2026 indicates this CVE was among a set of SQLite advisories identified as LLM-fabricated and subsequently withdrawn by national cybersecurity agencies including BSI and NCSC-NL.

Mitigation and workarounds

No mitigation is required, as CVE-2026-51294 has been officially rejected and is not a valid security vulnerability. Organizations should disregard any advisories or alerts referencing this CVE ID. If automated vulnerability scanners flag this CVE, the finding should be marked as a false positive based on the official rejection status (Github Advisory).

Community reactions

CTI Pilot reported on August 4, 2026 that BSI and NCSC-NL withdrew SQLite-related advisories — including this CVE — after determining they were fabricated by large language models (LLMs) rather than discovered through legitimate security research. This incident highlights growing concerns in the security community about AI-generated vulnerability reports polluting CVE databases and consuming analyst resources. The programmervuln/cveadvisory- GitHub repository, which served as the primary reference for this CVE, has been identified as a source of fabricated advisories.

Additional resources


SourceThis report was generated using AI

Related SQLite vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-51295NONEN/A
  • SQLite logoSQLite
  • sqlite
NoNoJul 30, 2026
CVE-2026-51294NONEN/A
  • SQLite logoSQLite
  • sqlite
NoNoJul 30, 2026
CVE-2026-51293NONEN/A
  • SQLite logoSQLite
  • sqlite
NoNoJul 30, 2026
CVE-2026-51292NONEN/A
  • SQLite logoSQLite
  • sqlite
NoNoJul 30, 2026
CVE-2026-51291NONEN/A
  • SQLite logoSQLite
  • sqlite
NoNoJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management