CVE-2026-51297
HIGHSQLite 3.41 - Use-After-Free in JSON Parser via Malicious JSON Payload
Title source: llmDescription
sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead to arbitrary code execution, sensitive information leakage and service denial.
References (2)
Core 2
Scores
CVSS v3
8.8
EPSS
0.0034
EPSS Percentile
27.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (1)
sqlite/sqlite
3.41.0
Published
Jul 27, 2026
Tracked Since
Jul 27, 2026