Hallucinated “Critical” SQLite CVEs from LLM Slop

“The scariest SQLite vulnerability of 2026 doesn’t exist. An LLM invented it anyway—and the government listed it as critical.”

The Story

An unknown GitHub account published more than 50 SQLite vulnerability advisories that NVD and CISA listed as critical. JFrog’s audit found 54 were fabricated by LLMs, citing nonexistent functions, wrong line numbers, invalid proof-of-concepts, and code that never existed. One contained a kernel of a real bug wrapped in fake metadata.

Why It Matters

AI slop has escaped chat interfaces and is polluting the institutional infrastructure of software security—the official databases humans and agents trust.

Evidence

JFrog Security Research (Hacker News top story, roughly 127 points).

Sources

Daily scan: 2026-08-03