2026-08-03 / Signal #2
Hallucinated “Critical” SQLite CVEs from LLM Slop
“The scariest SQLite vulnerability of 2026 doesn’t exist. An LLM invented it anyway—and the government listed it as critical.”
The Story
An unknown GitHub account published more than 50 SQLite vulnerability advisories that NVD and CISA listed as critical. JFrog’s audit found 54 were fabricated by LLMs, citing nonexistent functions, wrong line numbers, invalid proof-of-concepts, and code that never existed. One contained a kernel of a real bug wrapped in fake metadata.
Why It Matters
AI slop has escaped chat interfaces and is polluting the institutional infrastructure of software security—the official databases humans and agents trust.
Evidence
JFrog Security Research (Hacker News top story, roughly 127 points).
Sources
Daily scan: 2026-08-03