CVE-2026-51297

high

Description

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead to arbitrary code execution, sensitive information leakage and service denial.

References

https://github.com/sqlite/sqlite/blob/master/src/json.c

https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51297

Details

Source: Mitre, NVD

Published: 2026-07-27

Updated: 2026-07-28

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00344