Research · curated 3 Aug 2026

SQLite Critical CVEs or LLM Slop? - JFrog Security Research

Coverage timeline

3 Aug 2026jfrog.com

Why it matters

AI-generated false vulnerability reports are polluting NVD, CISA, and vendor CVE feeds with bogus critical ratings, wasting defender triage effort and undermining trust in vulnerability tracking.

JFrog Security Research investigated a batch of 50+ CVEs (including SQLite advisories like CVE-2026-51302) published by a newly created GitHub repo (programmervuln/cveadvisory-) and concluded they are LLM-generated 'slop': the cited code doesn't exist in the referenced versions, PoC payloads fail to trigger crashes under AddressSanitizer, none appear on SQLite's official advisory page, and AI-detection tools flag the advisories. NVD flagged them critical and Red Hat initially scored CVE-2026-51302 at 10.0 before downgrading to 7.6.