Research · curated 3 Aug 2026
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
First reported jfrog.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI-generated bogus vulnerability advisories are polluting authoritative sources like NVD, CISA, and Red Hat, wasting defender triage effort and eroding trust in the CVE ecosystem.
JFrog Security researchers investigated a batch of 50+ SQLite CVE advisories published from a newly created GitHub repo (programmervuln/cveadvisory-) and concluded they are LLM-generated 'slop' — the cited code didn't exist in the referenced versions, PoC payloads failed to trigger crashes under AddressSanitizer, none appeared on SQLite's official advisory page, and GPTZero flagged the advisories as AI-generated. Despite this, NVD flagged them critical and CISA's ADP concurred, with Red Hat initially scoring CVE-2026-51302 a 10.0 before downgrading to 7.6.