FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.
cve · CVE-2026-51303
Coverage timeline
0
first 2026-08-04 → last 2026-08-04
no data
Peak priority
—
no matching entries
Sources cited
0
0 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
Story timeline
No published entries reference this entity yet.
Entries about FABRICATED / NOT A REAL VULNERABILITY — one of the LLM-generated SQLite advisories published via the programmervuln/cveadvisory- GitHub repository. JFrog Security Research reproduction-tested it under AddressSanitizer against the claimed SQLite release and it did not reproduce; it claimed a fix in 3.51.3 although a 3.51.2-to-3.51.3 diff shows no changes to src/expr.c at all. NCSC-NL withdrew NCSC-2026-0268 on 2026-08-03 stating the CVE was hallucinated by an LLM, and BSI CERT-Bund withdrew WID-SEC-2026-2581 and WID-SEC-2026-2604 the same day. Recorded here so a scanner or triage lookup resolves to the retraction — do NOT open remediation work from this id.
No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.