Critical CVE issued for hallucinated SQLite vulnerability

Security researchers have identified a batch of fake SQLite vulnerability reports that appear to be generated by AI. These 'hallucinated' CVEs were initially flagged as critical by automated systems before being debunked by technical analysis.
Why it matters
The proliferation of AI-generated false security advisories poses a significant risk to the integrity of cybersecurity databases and automated vulnerability management.
Over the past few days, a newly created GitHub repo ( programmervuln/cveadvisory- ) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one). NVD quickly flagged these as critical, and CISA's ADP agreed. But when JFrog security researchers dug in to verify, the claims fell apart:
Combining all advisories into one file triggers AI-generated content warnings
This made us question the reliability of these CVEs as well as understanding that these CVEs may be LLM slop.
While investigating one of the CVEs yesterday, CVE-2026-51302, we saw that Red Hat initially assigned it a 10.0 Critical severity score:
Looking at the CVE again today, we noticed that the score has since been downgraded to 7.6 High.
To verify these reports thoroughly, we established an isolated testing workflow:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in