Executive brief
SQLite, a widely used database engine, contains a flaw in how it handles certain JSON data operations. An attacker could exploit this to crash applications using the database or potentially access sensitive information stored in the system's memory. This could lead to service interruptions or unauthorized data exposure in environments that process untrusted JSON input.
Technical details
A use-after-free vulnerability exists in SQLite 3.41 within the jsonRemoveFunc function of the JSON module. The vulnerability is caused by the parsed JSON object being freed at line 3555, while a subsequent call to jsonLookupStep at line 3575 continues to use the now-released pointer. A remote attacker providing specially crafted JSON input can trigger this flaw. Successful exploitation can result in a Denial of Service (DoS) via application crash or the leakage of sensitive heap memory information.
Affected products
- SQLite SQLite 3.41
Timeline
- 2026-07-27: disclosed: CVE-2026-51296 published