Skip to content
major vulnerability· requires attention

SQLite is a ubiquitous embedded DB used across apps, browsers, mobile and servers; a high-severity UAF enabling crash/memory leakage is widely impactful and newsworthy.

Applications

CVE-2026-51300

9.1
Critical
EPSS n/aJul 28, 2026

Use-after-free in SQLite 3.41 allows crash and memory disclosure via crafted SQL.

This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.

executive summary
technical analysis
affected
SQLite 3.41Applications embedding vulnerable SQLite (browsers, mobile apps, servers)IoT devices using SQLite
impact

Crafted SQL triggers a use-after-free, causing application crashes and leakage of sensitive memory; may enable further exploitation in some embedding contexts.

action required

Immediate action required

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free