CVE-2026-11824: Sqlite

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

Affected products

  • Sqlite Sqlite: before 3.53.2 (fixed in 3.53.2)

Published 2026-06-09. Last modified 2026-07-23.