{
  "id": 87378,
  "title": "Critical CVE issued for hallucinated SQLite vulnerability",
  "url": "https://urgent.news/2026/08/03/critical-cve-issued-for-hallucinated-sqlite-vulnerability",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-03T11:28:54.000Z",
  "source": {
    "name": "Hacker News Best",
    "slug": "hacker-news-best",
    "url": "https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/"
  },
  "original_language": "en",
  "account": "On July 30th, 2026, Afek Berger, a researcher from JFrog Security, issued a warning about a critical CVE related to a hallucinated vulnerability in SQLite. The vulnerability advisory was posted in a newly created GitHub repository along with 50 other false CVEs. The National Vulnerability Database (NVD) and the Cybersecurity and Infrastructure Security Agency (CISA) quickly flagged these as critical, but JFrog's researchers found the claims to be false. They discovered that the claimed heap use-after-free issue did not exist, as the SQLite function in question simply recycles register indices, making a use-after-free situation impossible by design. Similarly, the claims of other vulnerabilities, such as ExprListDelete() failing to clear back-references and UAF in sqlite3ExprDelete(), were found to be fabricated, with no evidence to support these claims. The fabricated CVE submissions entered the vulnerability database without proper proof-of-concept testing, resulting in wasted time and resources for organizations investigating and patching non-existent vulnerabilities. This incident highlights the need for a more rigorous verification process for vulnerability claims and the potential risks posed by automated vulnerability ingestion systems.",
  "summary": "Article URL: https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ Comments URL: https://news.ycombinator.com/item?id=49154332 Points: 305 # Comments: 91",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}