DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade to the latest secure release of SQLite that contains the fix for the use‑after‑free in expression parsing.
- If an upgrade is not immediately possible, isolate the SQLite process in a sandbox or container and restrict network access to only trusted clients to limit the exposure of the vulnerable database interface.
- Implement strict input validation and prepare statements so that user-supplied data is not directly interpreted as part of the query text.
Generated by OpenCVE AI on July 30, 2026 at 02:12 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
cvssV3_1
|
Fri, 31 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability exists in the expression parsing and memory management logic of SQLite 3.41. After invoking sqlite3ExprDelete to release an expression object, the program still retains the dangling pointer and subsequently accesses member fields of the already freed memory. By constructing malicious SQL queries, a remote attacker can trigger invalid memory access, leading to application crash and sensitive memory information leakage. | DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | sqlite: SQLite: Application crash and information leakage due to use-after-free | |
| Weaknesses | CWE-416 CWE-825 |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 27 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sqlite
Sqlite sqlite |
|
| Vendors & Products |
Sqlite
Sqlite sqlite |
Mon, 27 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability exists in the expression parsing and memory management logic of SQLite 3.41. After invoking sqlite3ExprDelete to release an expression object, the program still retains the dangling pointer and subsequently accesses member fields of the already freed memory. By constructing malicious SQL queries, a remote attacker can trigger invalid memory access, leading to application crash and sensitive memory information leakage. | |
| References |
|
Status: REJECTED
Assigner: mitre
Published:
Updated: 2026-07-31T14:34:35.949Z
Reserved: 2026-06-07T00:00:00.000Z
Link: CVE-2026-51300
Updated:
Status : Rejected
Published: 2026-07-27T16:17:39.153
Modified: 2026-07-31T15:17:27.450
Link: CVE-2026-51300
OpenCVE Enrichment
Updated: 2026-07-30T02:15:03Z