AI-Generated Fake CVEs Mislead SQLite Vulnerability Reporting

AI-Generated Fake CVEs Mislead SQLite Vulnerability Reporting

First seen 4 Aug 2026, 02:19 UTC TheregisterXenospectrumwww2.sqlite.orgresearch.jfrog.comwww.cve.org 90% similarity 52.5

Article Content

Browse articles
ThreatCluster

Six vulnerabilities in SQLite, published as CVEs on July 27, 2026, were retracted four days later after being found to be fabricated. JFrog tested the claims and confirmed that none of the vulnerabilities existed in the code, with CVSS scores ranging from 7.5 to 9.8 assigned by CISA. The vulnerabilities were linked to a new GitHub repository that submitted questionable CVEs. JFrog's analysis showed that the reported functions and line numbers were fictitious, leading to MITRE rejecting all six CVEs on July 31. This incident highlights vulnerabilities in the CVE pipeline, exacerbated by NIST's backlog in processing submissions. The findings suggest that AI-generated reports could continue to infiltrate the ecosystem if verification processes are not improved.

Key Points: • Six bogus CVEs for SQLite were published and later retracted after testing. • JFrog confirmed that none of the vulnerabilities existed in the tested SQLite versions. • The incident reveals significant flaws in the CVE reporting and verification process.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
CVE-2026-51300 and CVE-2026-51303 published
Six CVEs claiming vulnerabilities in SQLite were published, with high CVSS scores assigned.
Xenospectrum
2026-07-31
MITRE rejects all six CVEs
MITRE changed the status of the six CVEs to REJECTED after determining they were not security issues.
Xenospectrum
Recent
JFrog tests CVEs and finds them fake
JFrog tested the reported vulnerabilities and found no reproducible issues, confirming they were fabricated.
Theregister

Community

Browse all →