CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50812

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-07-08
A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.

CSIRTS triage

What
SQLite has vulnerabilities that can lead to denial of service and potential information disclosure.
Who is affected
Users of SQLite that utilize the Session Extension.
Urgency
Remediation is necessary to prevent potential crashes and information leaks.
Action
Users should apply the latest updates to SQLite.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-50812

Get an email if CVE-2026-50812 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-50812

CVE.org record

Embed the live status

CVE-2026-50812 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50812 status](https://www.csirts.com/badge/CVE-2026-50812)](https://www.csirts.com/cve/CVE-2026-50812)