Skip to main content
Version: v1.2.x

CVE-2026-50812

CVE Details

Visit the official vulnerability details page for CVE-2026-50812 to learn more.

Initial Publication

07/08/2026

Last Update

07/09/2026

Third Party Dependency

sqlite-libs

NIST CVE Summary

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.

CVE Severity

5.5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.2⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.