CVE-2026-11824Disclosure(sqlite / sqlite)
LOWCVSS 8.5 · HIGHSignal is active with 1 mentions in latest observed window
Immediate actions
- Patch sqlite sqlite systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
Sources & remediation
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- sqlite
Threat summary
- Patch or workaround signal is available
- 2 mentions across 2 observed days
- Momentum state: stable
What's happening
- Patch or workaround mentioned in 1 signal
- Technical details provided in 1 signal
- Disclosure: 1 classified signal
- Peaked 1d ago at 1 mentions (2026-06-17); latest day: 1
- 2 total mentions across 2 days
Affected systems
Deep dive
Activity timeline2 mentions / 2d
Signal classification2 categories
Referenced assets1 URL
Classification over time
| Date | Total | Labels |
|---|
| 2026-06-17 | 1 | Disclosure1 |
| 2026-06-18 | 1 | Patch1 |
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | sqlite | sqlite | - | - | - |
