


Perceptive Security
SOC/SIEM Consultancy

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 21:05:50
Source:
nvd.nist.gov
Database & Storage, Zero-Day Vulnerabilities
SQLite version 3.41 contains a use-after-free vulnerability in the jsonCacheInsert function located in the json.c source file, which is part of the JSON cache management module. Use-after-free vulnerabilities can lead to memory corruption, potentially allowing attackers to execute arbitrary code or cause application crashes. The vulnerability has been assigned CVE-2026-51291 and is currently awaiting full analysis by NVD. The affected component is specifically the JSON caching mechanism introduced in SQLite's JSON extension. SQLite is widely embedded in countless applications, operating systems, and platforms, making this vulnerability potentially high impact. A proof-of-concept advisory has been published on GitHub alongside a reference to the affected source file in the official SQLite repository. Organizations and developers using SQLite 3.41 should monitor for patches and apply updates when available.
Technical details
Mitigation steps:
Affected products:
SQLite 3.41
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51291
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51291
https://github.com/sqlite/sqlite/blob/master/src/json.c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
