CVE-2025-7458: Sqlite

Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

Affected products

  • Sqlite Sqlite: from 3.39.2, before 3.41.2 (fixed in 3.41.2)

Published 2025-07-29. Last modified 2026-06-17.