JFrog finds 54 of 55 SQLite CVE advisories fabricated, likely AI-generated
JFrog Security Research found 54 of about 55 SQLite vulnerability advisories in a GitHub repository were fabricated, likely LLM-generated, including six rated critical or high.
JFrog Security Research found that 54 of roughly 55 vulnerability advisories in a public GitHub repository were completely fabricated, most likely generated by a large language model, according to analysis it published July 30, 2026. The findings drew renewed attention on August 3 as developers circulated them more widely.
The advisories included six SQLite CVEs rated critical or high that, on inspection, described bugs that do not exist. According to JFrog researcher Afek Berger, the entries referenced functions that are not in the code, used wrong function signatures, and cited out-of-range line numbers (one advisory pointed to line 3,575 in a file only 2,706 lines long), along with code changes that never occurred between the versions named.
The fabricated reports were not harmless paperwork. Red Hat had already downgraded one of them, CVE-2026-51302, from a maximum 10.0 severity score to 7.6. None of the six appear on SQLite’s official advisory page, and JFrog said all six triggered AI-generated-content warnings when run through the GPT Zero detector.
The episode points to a growing problem: LLM-generated ‘slop’ entering the vulnerability-disclosure pipeline, where a plausible-looking CVE can consume triage time at every downstream project and vendor before anyone confirms the bug is fake. Automated advisory generation makes producing such reports nearly free.
The analysis rests on a single research team’s review and covers one repository, so it does not establish how widespread fabricated advisories are across the CVE system. It does show that severity ratings and official-looking metadata alone are no longer proof a vulnerability is real.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
