NCSC-2026-0268 [1.01] [M/H] Vulnerability patched in SQLite by SQLite Consortium (withdrawn)
~~SQLite Consortium has patched a vulnerability in SQLite version 3.41.~~ UPDATE CVE is withdrawn; the "vulnerability" is very likely hallucinated by an LLM. See attached source for more information. ~~The vulnerability concerns a use-after-free in the expression evaluation logic of SQLite. An attacker can remotely exploit this vulnerability by providing specially crafted malicious SQL statements. Exploitation can lead to arbitrary code execution, leaking sensitive information, or causing a denial of service. The vulnerability arises from improper memory management during expression evaluation. Systems using SQLite, including products from Red Hat, are affected.~~
CSIRTS triage
- What
- A CVE reported for SQLite 3.41 has been withdrawn as likely fabricated.
- Who is affected
- No real vulnerability exists; the CVE is hallucinated.
- Urgency
- Not urgent; this is a false alarm and no actual vulnerability exists.
- Action
- Disregard this advisory; no patching is required.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SQLite
Get an email when a new SQLite advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0268
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-51302 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for SQLite by SQLite
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highGHSA-wpmr-8h3q-fwj7: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on…ghsa · 2026-09-10
- highCVE-2025-70873: An information disclosure issue in the zipfileInflate function in the zipfile extension in SQL…msrc · 2026-09-08
- medium[UPDATE] [medium] NetApp ActiveIQ Unified Manager for VMware vSphere (Glib, SQLite): Multiple vulnerabilitiescert-bund · 2026-09-01
- unknownCVE-2026-77846: Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project a…nvd · 2026-08-30
- unknownCVE-2026-54687: n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, no…nvd · 2026-08-27
- medium[NEW] [medium] SQLite: Vulnerability allows denial of servicecert-bund · 2026-08-26
More from NCSC-NL Advisories
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able2026-09-11