Skip to content
← All news
4 min read

Six critical SQLite CVEs look like LLM slop, and they made it into official databases

JFrog tested six critical-rated SQLite advisories: nonexistent functions, impossible line numbers, proof-of-concept payloads that crash nothing. They still entered NVD, GHSA, and CISA's pipeline.

Six critical SQLite CVEs cite functions that do not exist. Red Hat scored one 10.0 anyway.

JFrog's security research team published an analysis on July 30, 2026 arguing that six critical-rated SQLite CVEs are fabrications, most likely LLM-generated, and that they cleared every gate in the official vulnerability pipeline anyway: NVD, GitHub's advisory database, and CISA's Authorized Data Publisher system. Red Hat initially scored one of them 10.0, the maximum severity that exists, before downgrading it to 7.6.

The tells

The six advisories, CVE-2026-51296, 51297, 51300, 51302, 51303, and 51304, came from a GitHub repository called programmervuln that boasts of publishing more than 50 CVEs, which its own description says are 'LLM slop except from one.' JFrog tested the claims the boring way: reading the source, building the named versions in Docker, and running the proof-of-concept payloads under AddressSanitizer. The advisories reference functions that do not exist in the cited versions, or that were only added to SQLite later. One cites line numbers beyond the end of a 2,706-line file. None of the payloads produced a crash. None of the six appears on SQLite's own advisory page.

The pipeline is the story

A fake CVE is not new. Six fake critical CVEs against one of the most deployed pieces of software on earth, passing into the databases that every dependency scanner, security dashboard, and compliance auditor treats as ground truth, is the story. The vulnerability pipeline was built to catch missing reports, not fabricated ones, and generative models have made fabrication free. The economics now run the wrong way: filing slop costs nothing and farms reputation, while disproving one advisory took a professional research team source inspection, container builds, and sanitizer runs.

JFrog's case is strong but circumstantial on authorship: AI-detection tools flagging the text is weak evidence on its own, and the authors have not confirmed anything. What is not in dispute is that the technical claims fail checks.

Why a build studio cares

SQLite is in practically everything we ship, from build tooling to the browsers our sites run in. When a fake 10.0 lands in NVD, scanners light up, clients ask questions, and someone has to spend an afternoon proving a negative. Alert fatigue is the real damage: a pipeline that cries critical on fabricated advisories trains teams to ignore it, which is exactly the wrong reflex for the day a real one lands.

Next step: read JFrog's full analysis. If your dependency alerts need triage that separates real risk from noise, write to us at hello@gattyworks.com.

SecurityDev ToolsAI SlopSQLiteCVEJFrogAISlopNVDVulnerabilityManagementAppSecDevSecOpsLLMCybersecurity

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.