top of page
perceptive_background_267k.jpg

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by…

Published:

27 juli 2026 om 00:00:00

Alert date:

27 juli 2026 om 22:03:54

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Zero-Day Vulnerabilities

SQLite version 3.41 contains a use-after-free vulnerability in its JSON parsing logic. Remote adversaries can craft malicious JSON payloads to trigger a memory free operation followed by illegal memory access. Successful exploitation may lead to arbitrary code execution, sensitive information leakage, or denial of service. The vulnerability is remotely exploitable, increasing its severity. It has been assigned CVE-2026-51297 and is tracked by NVD. A proof-of-concept advisory has been published on GitHub. The affected source file is identified as json.c in the SQLite repository.

Technical details

Mitigation steps:

Affected products:

SQLite 3.41

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page