10 hours ago
- A GitHub repo published multiple SQLite vulnerability advisories that were quickly flagged as critical by NVD and CISA, but JFrog researchers found them to be AI-generated and false.
- The advisories cited non-existent code, referenced functions that didn't exist in the claimed versions, and provided PoCs that failed to trigger any crashes.
- None of the CVEs appeared on SQLite's official advisory page, and AI detection tools flagged the content as machine-generated.
- Red Hat initially assigned a 10.0 critical score to CVE-2026-51302 but later downgraded it to 7.6 high after further review.