CVE-2026-51297

Source
https://cve.org/CVERecord?id=CVE-2026-51297
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-51297.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-51297
Aliases
Downstream
Published
2026-07-27T00:00:00Z
Modified
2026-07-31T03:47:28.582975089Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead to arbitrary code execution, sensitive information leakage and service denial.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/51xxx/CVE-2026-51297.json"
}
References

Affected packages

Git / github.com/sqlite/sqlite

Affected ranges

Type
GIT
Repo
https://github.com/sqlite/sqlite
Events
Database specific
Show details
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:sqlite:sqlite:3.41.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.41.0"
        },
        {
            "last_affected": "3.41.0"
        }
    ]
}

Affected versions

3.*
3.41.0
version-3.*
version-3.41.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-51297.json"