CVE-2026-51296
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedSQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQLite JSON module. The parsed JSON object is freed at line 3555, while line 3575 still calls jsonLookupStep with the released pointer. Remote attackers can exploit this flaw to crash the service and leak heap memory information. Source description excerpt; complete tracked detail loads below.
NVD published: Jul 27, 2026 · Source record updated: Aug 1, 2026 · Tracker snapshot: Aug 8, 2026
What is affected
ReportedSQLite — SQLite. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Jul 27, 2026 · Source record updated: Aug 1, 2026 · Tracker snapshot: Aug 8, 2026
Urgency and basis
ReportedTrack · 117.5
Tracker decision tier from the evidence detailed below · Source record updated: Aug 1, 2026 · Tracker snapshot: Aug 8, 2026
Exploitation evidence
Not reportedNot reported by tracked sources.
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…