Post #4360357
2026-08-03 17:07 UTC
So, for the three people that haven't seen it: MITRE waved through a bunch of bogus vulnerabilities in SQLite and issued CVEs.
Primary reporting: https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
SQLite Forum Thread: https://sqlite.org/forum/forumpost/34bdf3b9bd759d4d
IFIN thread: https://discourse.ifin.network/t/sqlite-critical-cves-or-llm-slop-jfrog-security-research/
I am very much not surprised that this happens (having seen the bottom-of-the-barrel vulnerabilities that this program has to deal with) but I am honestly surprised that it happened with this quantity for a well-known project. I'd be curious if there was any communication between MITRE & SQLite or even reporting attempts to SQLite in the first place...
Replies (2)
-
@nyanbinary@infosec.exchange 2026-08-03 17:09
Oh, perfect moment to mention my previous post on MITRE CVE data quality :3 https://blagh.nyanbinary.de/posts/look-ma-im-a-cve-reference/
-
@hyc@mastodon.social 2026-08-03 21:57
@nyanbinary@infosec.exchange IME these "researchers" never practice responsible disclosure. The last CVE one of these clowns filed against my stuff, I only discovered because I have google alerts set on my keywords. https://bugs.openldap.org/show_bug.cgi?id=10421 They're the same lowlife scum as bounty hunters, chasing profit while totally lacking the ability to build anything useful themselves. They get accolades while they shit on actual developers. https://clip.cafe/star-wars-episode-v-the-empire-strikes-back-1980/bounty-hunters-we-dont-need-their-scum/.