Research · curated 3 Aug 2026

SQLite Critical CVEs or LLM Slop? - JFrog Security Research

Coverage timeline

3 Aug 2026jfrog.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI-generated bogus vulnerability advisories are polluting authoritative sources like NVD, CISA, and Red Hat, wasting defender triage effort and eroding trust in the CVE ecosystem.

JFrog Security researchers investigated a batch of 50+ SQLite CVE advisories published from a newly created GitHub repo (programmervuln/cveadvisory-) and concluded they are LLM-generated 'slop' — the cited code didn't exist in the referenced versions, PoC payloads failed to trigger crashes under AddressSanitizer, none appeared on SQLite's official advisory page, and GPTZero flagged the advisories as AI-generated. Despite this, NVD flagged them critical and CISA's ADP concurred, with Red Hat initially scoring CVE-2026-51302 a 10.0 before downgrading to 7.6.