Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlaruncompress(), sqlite3valueint64(), sqlite3malloc(int), uncompress() components
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39113.json",
"cna_assigner": "mitre"
}[
{
"id": "CVE-2026-39113-531777ea",
"target": {
"file": "src/btree.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"70446409330231105630817689568687018938",
"338906070429696790328088559243218733209",
"255039354024633570035412844728542128564",
"95807499626319381507986151421634668296",
"300076277947233735737192518808595462489",
"323839119980907498800290193789273744406",
"99444959544205514057622809684528590749",
"180555414129757407767537164972317733340",
"289661608673300533498366352938162729282",
"310704964454642143339741340863407273820",
"256477658491084357048132423930609942323",
"66327148346417501552611537928305664344",
"214533049578149424180611220920267072513",
"6340545679213454599365364426266647806",
"47576465790459269984424743983710152288",
"112265664825054872672980918515713743606"
]
},
"signature_version": "v1",
"source": "https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508",
"signature_type": "Line"
},
{
"id": "CVE-2026-39113-5dae3be3",
"target": {
"file": "ext/misc/sqlar.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"186308204391328178205455952600612171166",
"333116856949043857163447439002107089915",
"306872792261211558871987797263345673910",
"156711292062885821676058205943622143741"
]
},
"signature_version": "v1",
"source": "https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508",
"signature_type": "Line"
},
{
"id": "CVE-2026-39113-94793250",
"target": {
"file": "src/json.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"245340927660686962636599166810421957218",
"299576465675806713868041488725485073758",
"95788352312924315563398396779279528790",
"232531396685824234138573054246956627875",
"62783679667153149563230755044255285032",
"331834455327748000833370789679489220064",
"284432948561962889678815822853373834831",
"75063160214412479144823946790340233073",
"43978437521099903195400238280726206239",
"331834455327748000833370789679489220064",
"284432948561962889678815822853373834831",
"8758012732373156881421587231759496269",
"299457937081955598215910202536370444327",
"146345745351453325017492615837168303708",
"327856923148591433402808128417772206243",
"136989473060797992817304410991808756444"
]
},
"signature_version": "v1",
"source": "https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508",
"signature_type": "Line"
},
{
"id": "CVE-2026-39113-b6542f3c",
"target": {
"function": "btreeParseCellPtr",
"file": "src/btree.c"
},
"deprecated": false,
"digest": {
"function_hash": "246909833509192720337295822396436519122",
"length": 1626.0
},
"signature_version": "v1",
"source": "https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508",
"signature_type": "Function"
},
{
"id": "CVE-2026-39113-c6a76bd5",
"target": {
"function": "jsonBlobEdit",
"file": "src/json.c"
},
"deprecated": false,
"digest": {
"function_hash": "73553111718916123162515930080493152692",
"length": 695.0
},
"signature_version": "v1",
"source": "https://github.com/sqlite/sqlite/commit/169f68ed88b34cb68f720191c64c058f2ccec508",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39113.json"
"2026-08-27T19:14:09Z"