What is CVE-2026-51296?
A use-after-free vulnerability exists in the jsonRemoveFunc function of SQLite 3.41's JSON module. The flaw allows remote attackers to crash the service and leak heap memory information by exploiting the released JSON object pointer. Systems using SQLite should be updated to the latest version immediately.
Azərbaycanca: SQLite 3.41-in JSON modulunda jsonRemoveFunc funksiyasında istifadədən sonra azad etmə (use-after-free) boşluğu aşkar edilib. Bu zəiflik uzaqdan hücum edən şəxsə xidməti çökdürməyə (DoS) və heap yaddaş məlumatlarının sızmasına imkan verir. SQLite istifadə edən sistemlər dərhal son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
How can CVE-2026-51296 affect systems using SQLite?
This flaw allows a remote attacker to crash the service (DoS) and leak heap memory information by exploiting the use-after-free vulnerability in the jsonRemoveFunc function.
What action should be taken to mitigate the risk associated with CVE-2026-51296?
Systems using SQLite should be updated to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.