Junglewise Threat Intelligence

CVE-2026-51297: SQLite use-after-free in JSON parsing logic

CVE-2026-51297 · Severity: info · CVSS 7.5 · Published 2026-07-27

Executive brief

SQLite, a widely used database engine, contains a memory management flaw in its JSON processing component. An attacker can exploit this by providing specially crafted JSON data to a database query, potentially causing the application to crash, leak sensitive information, or allow unauthorized code execution. This affects any application that uses SQLite 3.41 to process untrusted JSON input.

Technical details

A use-after-free vulnerability exists in the JSON parsing module of SQLite 3.41. The flaw is located in the interaction between jsonParseFree() and jsonBlobEdit() within src/json.c. When processing malformed JSON (such as a truncated literal), the parser may enter an error-handling branch that deallocates a JsonParse heap object via jsonParseFree() but fails to nullify the pointer. Subsequent logic in jsonBlobEdit() then accesses this dangling pointer. A remote attacker capable of executing SQL queries with controlled JSON input can trigger this vulnerability to achieve out-of-bounds heap access, resulting in a denial of service (segmentation fault), information disclosure of heap contents, or arbitrary code execution.

Affected products

  • SQLite SQLite 3.41

Timeline

  • 2026-07-27: disclosed: Vulnerability published to NVD and detailed advisory released on GitHub.

References