Hacker News discussion: Critical CVE issued for hallucinated SQLite vulnerability
Hacker News readers are discussing "Critical CVE issued for hallucinated SQLite vulnerability" with 300 points and 91 comments.
Follow Hacker News AI to make it a durable For You signal.
JFrog researchers say a GitHub account published a batch of fabricated or AI-generated SQLite vulnerability advisories that were nevertheless entered into vulnerability-tracking systems and initially received critical ratings. In tests of six reported flaws, the researchers found references to functions or line numbers absent from the claimed SQLite versions, nonexistent fixes, invalid proof-of-concept queries, and no crashes under AddressSanitizer; they also noted that none appeared on SQLite’s official advisory page. A broader review of 55 advisories from the account reportedly found 54 fabricated and one real bug accompanied by unverified metadata. One SQLite CVE, CVE-2026-51302, was initially rated 10.0 Critical by Red Hat before being downgraded to 7.6 High. The researchers attribute the incident to weaknesses in the CVE intake and enrichment process, including the lack of required reproduction or identity verification, and say they reported their findings to GHSA, Red Hat, and NVD. They warn that false high-severity records can waste security teams’ time, pollute databases, and misdirect automated vulnerability-triage or remediation systems.