SQLite patched CVE-2026-11824, a high-severity heap buffer overflow in the FTS5 full-text search extension, in release 3.53.2. The flaw stems from an integer underflow in fts5ChunkIterate() and affects SQLite versions prior to 3.53.2 when compiled with SQLITE_ENABLE_FTS5. According to public reporting and SQLite's vulnerability listings, the bug can be triggered when an application opens a crafted database file and runs an FTS5 MATCH query.
Successful exploitation could cause a denial of service and may enable arbitrary code execution in affected applications. The issue requires specific conditions—most notably that the target accepts an untrusted SQLite database and uses FTS5 search features—but SQLite's broad use across software and embedded products makes the exposure significant. SQLite addressed the bug with fixes incorporated before the 3.53.2 release and published the update in its official release log and CVE documentation.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Unity Linux published advisory UTSA-2026-104747 for Unity Linux 20 systems with affected SQLite packages, remediating CVE-2026-11824 by updating SQLite to a fixed version. The advisory notes the flaw affects FTS5-enabled applications using SQLite versions before 3.53.2.
SQLite's vulnerabilities page included CVE-2026-11824 among documented security issues affecting the project.
ZeroPath published a technical analysis of CVE-2026-11824 describing the bug as a high-severity heap buffer overflow reachable by opening a crafted database and executing an FTS5 MATCH query, with possible denial of service or arbitrary code execution.
SQLite released version 3.53.2, which patched CVE-2026-11824, a heap buffer overflow in the FTS5 full-text search extension affecting versions prior to 3.53.2 when built with SQLITE_ENABLE_FTS5.
SQLite added fix commits addressing an integer underflow in the FTS5 function fts5ChunkIterate(), the flaw later tracked as CVE-2026-11824. The ZeroPath analysis also notes a regression test was published in the official source tree.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcesqlite.org
Open sourcezeropath.com
Open sourcesqlite.org
Open sourcesqlite.org
Open sourcesqlite.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.