AI-Generated Fake CVEs Flood Vulnerability Databases
08 Aug 2026
Fabricated SQLite CVEs Reveal AI-Generated 'Slop' Flooding Vulnerability Databases
JFrog security researchers have uncovered dozens of fabricated SQLite CVEs — including one initially rated a maximum-severity 10.0 Critical — sitting inside the National Vulnerability Database (NVD) and CISA's Authorized Data Publisher (ADP) system. The finding raises fresh questions about how much organizations can trust the vulnerability data feeding their security tooling.
What happened
A GitHub account (programmervuln/cveadvisory-) published a batch of more than 50 SQLite vulnerability advisories. NVD and CISA's ADP flagged these submissions as critical, triggering downstream alerts across the security ecosystem.
JFrog researchers investigated the batch and expanded their audit to 55 advisories from the same account. The results were stark: 54 of the 55 advisories were completely fabricated. Only one contained a real bug — and even that one was wrapped in unverified metadata.
One advisory in particular, CVE-2026-51302, was initially assigned a 10.0 Critical severity score by Red Hat. It was later downgraded to 7.6 High, though the report does not detail exactly how or by whom the reassessment was conducted beyond Red Hat's involvement.
The timeline
- February 2024: NIST paused deep CVE analysis amid a surge in vulnerability report volume.
- The GitHub account published its batch of 50+ SQLite CVE advisories, which NVD and CISA's ADP flagged as critical.
- JFrog researchers investigated and audited 55 advisories from the account.
- CVE-2026-51302 was scored 10.0 Critical, then revised down to 7.6 High.
Sources do not clarify whether the advisories were generated directly via AI/LLM tools or through some other automated process — the "slop" framing describes the pattern of output rather than a confirmed generation method. The identity and motive of the GitHub account owner also remain unexplained.
Why this matters
Fabricated CVEs aren't just noise — they carry real operational cost. Organizations that trust flagged critical vulnerabilities may waste time investigating and patching issues that don't exist. At scale, this pollutes vulnerability databases and degrades their reliability as a trusted source of truth for security teams.
The risk compounds in environments where AI-driven systems automate vulnerability triage and remediation: an automated pipeline acting on a fabricated 10.0 Critical rating without human review could trigger unnecessary emergency patching cycles or, worse, misdirect attention away from real threats.
Compounding the problem, NIST's reduced capacity for deep CVE analysis since February 2024 may mean fewer unverified reports get caught before reaching "critical" status in public databases.
Why founders should care
For founders operating in or adjacent to cybersecurity, this incident is likely to be a signal worth watching, though its full scale of impact remains unclear from current reporting:
- Demand for CVE-authenticity scoring and automated advisory auditing tools may grow as organizations look to avoid wasting resources on fabricated threats.
- The apparent gap in NIST's vetting capacity could plausibly create room for third-party or automated vulnerability validation services to fill.
- Security tooling that cross-references CVE claims against reproducible proof-of-concept exploits could address a vetting gap this incident has exposed.
- Teams relying on AI for security triage without human-in-the-loop verification may face a higher probability of acting on fabricated or unverified threat data — a risk founders building AI-driven security products should factor into design.
- The inconsistency between CVE-2026-51302's initial and revised severity scores suggests current CVE assignment pipelines may not have uniform vetting standards, a gap that could inform product positioning for founders building in this space.
What's still unclear
Several open questions remain: how CVE-2026-51302's score was actually reassessed, how many organizations acted on the fabricated CVEs before they were caught, and what process — if any — NVD and CISA now use to prevent similar fabricated submissions going forward. Founders evaluating opportunities here should treat these gaps as areas requiring further diligence rather than assumptions.