


Perceptive Security
SOC/SIEM Consultancy

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by…
Published:
26 juli 2026 om 22:00:00
Alert date:
27 juli 2026 om 20:03:54
Source:
nvd.nist.gov
Database & Storage, Zero-Day Vulnerabilities
SQLite version 3.41 contains a use-after-free vulnerability in its JSON parsing logic. Remote adversaries can craft malicious JSON payloads to trigger a memory free operation followed by illegal memory access. Successful exploitation may lead to arbitrary code execution, sensitive information leakage, or denial of service. The vulnerability is remotely exploitable, increasing its severity. It has been assigned CVE-2026-51297 and is tracked by NVD. A proof-of-concept advisory has been published on GitHub. The affected source file is identified as json.c in the SQLite repository.
Technical details
Mitigation steps:
Affected products:
SQLite 3.41
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51297
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51297
https://github.com/sqlite/sqlite/blob/master/src/json.c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
