A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changesetapplyv3() applies a corrupt changeset and reaches sqlite3valuetype() with a NULL sqlite3_value pointer.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50812.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50812.json"
[
{
"target": {
"function": "sessionApplyOneOp",
"file": "ext/session/sqlite3session.c"
},
"deprecated": false,
"source": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d",
"id": "CVE-2026-50812-495b6467",
"signature_version": "v1",
"digest": {
"length": 2520.0,
"function_hash": "5283277949074340631478369519782904467"
},
"signature_type": "Function"
},
{
"target": {
"file": "ext/session/sqlite3session.c"
},
"deprecated": false,
"source": "https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d",
"id": "CVE-2026-50812-f33f1391",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"328633961636892699255186437233098241249",
"116829162221007310289753263995200573037",
"152798920715269222678320757873925502918",
"19329022112904728664882501055310768726"
]
},
"signature_type": "Line"
}
]
"2026-08-12T16:25:40Z"