MITRE rejected a batch of CVE reports affecting SQLite, libraw, and ESP32-audioI2S after researchers found the underlying claims were likely fabricated. An oss-sec post cited JFrog's review of recently published SQLite advisories and said some records had briefly appeared on cve.org before being withdrawn, underscoring how CVE Numbering Authorities often depend on submitter accuracy and may not be able to independently validate every report before publication.
JFrog said six SQLite entries—CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304—contained major inconsistencies, including references to nonexistent functions, invalid SQL, impossible code paths, mismatched line numbers, and proof-of-concept payloads that did not reproduce crashes. The researchers traced the advisories to a newly created GitHub repository and concluded they were largely AI-generated "LLM slop"; in a broader audit of 55 advisories from the same account, they found 54 appeared fabricated and one described a real bug but with unverified CVE metadata, raising concerns that false high-severity entries can pollute NVD and CISA enrichment pipelines and mislead automated vulnerability triage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Alan Coopersmith posted to the oss-sec mailing list on July 31, 2026, summarizing the rejected CVE reports and citing JFrog's findings on the SQLite entries. The post also noted that CVE Numbering Authorities often rely on submitter honesty because they may lack resources to independently verify every report.
On July 31, 2026, JFrog published an analysis of the SQLite CVE batch after testing the claims against official source code and proof-of-concept payloads. The researchers concluded the advisories were largely fabricated "LLM slop," citing nonexistent code references, invalid patches, and PoCs that failed to trigger the alleged bugs.
JFrog said it reported the fabricated CVE findings to GitHub Security Advisory, Red Hat, and NVD, after which Red Hat and NVD flagged or removed the affected CVE entries. GitHub had not removed the repository at the time of reporting.
MITRE rejected the entire set of questioned CVE entries referenced in the reporting, with the rejection reflected in a CVEProject cvelistV5 GitHub commit. This affected the disputed advisories tied to SQLite, libraw, and ESP32-audioI2S.
A newly created GitHub repository, programmervuln/cveadvisory, published a batch of vulnerability advisories, including many targeting SQLite as well as libraw and ESP32-audioI2S. Some of these CVEs were subsequently published on cve.org earlier in the same week.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetruesec.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourcereddit.com
Open sourceresearch.jfrog.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.