
JFrog: Six SQLite CVEs Rated Critical by NVD Are AI-Generated "LLM Slop" That Fail Technical Verification
JFrog researchers built SQLite 3.41.0, 3.51.2, and 3.51.3 in isolated Docker containers with AddressSanitizer and ran each disputed advisory's proof-of-concept SQL. No claimed use-after-free was reproduced. The CVEs had received 7.5–10.0 severity scores from NVD, propagated through CISA's ADP feeds, and reference functions absent from the pinned source version. Worth flagging: the CVE pipeline assigns scores before any source-level verification occurs.
Published