major vulnerability· requires attention
SQLite is a ubiquitous embedded DB used across apps, OSs and appliances; a remote UAF enabling RCE risks broad, high-impact disruption.
Applications
CVE-2026-51297
8.8
High
EPSS n/aJul 28, 2026
SQLite 3.41 JSON parsing use-after-free allows remote code execution.
This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.
executive summary
technical analysis
affected
SQLite 3.41Applications embedding SQLite (browsers, mobile apps, desktop apps)IoT devices and appliances using SQLite
impact
Remote attackers can trigger a use-after-free in JSON parsing to achieve RCE, data leakage, or service denial via crafted JSON.
action required
Immediate action required
how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references