What is CVE-2026-51297?
CVE-2026-51297 is a use-after-free vulnerability in the JSON parsing logic of SQLite 3.41. A remote attacker can craft a malicious JSON payload to trigger a memory free operation followed by illegal memory access, potentially leading to arbitrary code execution, sensitive information leakage, or denial of service (DoS). Immediate patching of the SQLite library to the latest secure version is strongly recommended.
Azərbaycanca: CVE-2026-51297 SQLite 3.41-in JSON analiz məntiqində aşkarlanmış "use-after-free" boşluğudur. Uzaqdan hücum edən şəxs sərbəst buraxılmış yaddaşa qanunsuz müraciəti tətikləyərək kod icrası, məlumat sızması və ya xidmət rəddi (DoS) yarada bilər. Dərhal SQLite kitabxanasını ən son təhlükəsizlik yeniləməsi ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which version of SQLite is affected by CVE-2026-51297?
This vulnerability was discovered in the JSON parsing logic of SQLite 3.41.
What are the potential impacts if CVE-2026-51297 is successfully exploited?
A remote attacker can trigger illegal memory access, potentially leading to arbitrary code execution, sensitive information leakage, or denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.