News · curated 3 Aug 2026
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
First reported jfrog.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
AI-generated fake vulnerability reports polluting the CVE/NVD pipeline erode trust in vulnerability data that defenders rely on for triage and patching, wasting analyst time and undermining supply-chain security processes that trust unverified submissions.
JFrog security researchers found that a batch of six critical- and high-rated SQLite CVEs (plus 50+ others covering libraw and ESP32-audioI2S) published by a new GitHub repo 'programmervuln/cveadvisory-' were bogus and appear to be LLM-generated 'slop'; the advisories cited non-existent functions and unrelated source lines, and their proof-of-concept payloads triggered no crashes when tested under AddressSanitizer. The fake reports nonetheless flowed into NVD with CISA enrichment before MITRE rejected the repo, exposing weaknesses in a CVE pipeline that operates largely on the honor system while NIST's NVD backlog exceeds 27,000 records.