Post

HN
Hacker News

Critical CVE issued for hallucinated SQLite vulnerability

Ranked #1 on Hacker News with 145 points and 36 comments.

Afek Berger, JFrog Security Researcher | 30 Jul, 2026

Over the past few days, a newly created GitHub repo ( programmervuln/cveadvisory- ) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one). NVD quickly flagged these as critical, and CISA's ADP agreed. But when JFrog security researchers dug in to verify, the claims fell apart:

Combining all advisories into one file triggers AI-generated content warnings

This made us question the reliability of these CVEs as well as understanding that these CVEs may be LLM slop.

While investigating one of the CVEs yesterday, CVE-2026-51302, we saw that Red Hat initially assigned it a 10.0 Critical severity score:

Looking at the CVE again today, we noticed that the score has since been downgraded to 7.6 High.