CVE-2025-70873: Sqlite
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
Affected products
- Sqlite Sqlite: before 3.51.1 (fixed in 3.51.1)
Published 2026-03-12. Last modified 2026-06-17.