CVE-2026-11824

HIGH CVSS 4.0: 8.5 EPSS 0.18%
Updated Jul 23, 2026
Sqlite
Parameter Value
CVSS 8.5 (HIGH)
Affected Versions before 3.53.2
Fixed In 3.53.2
Type CWE-122 (Heap-based Buffer Overflow)
Vendor Sqlite
Public PoC No

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Sqlite Sqlite
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
3.53.2