High severity7.5NVD Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-21227
CVE-2022-21227
Description
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sqlite3npm | >= 5.0.0, < 5.0.3 | 5.0.3 |
Affected products
3- sqlite3/sqlite3description
Patches
Vulnerability mechanics
References
9- github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4anvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9qrh-qjmc-5w2pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21227ghsaADVISORY
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2805470nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-SQLITE3-2388645nvdThird Party AdvisoryWEB
- github.com/TryGhost/node-sqlite3/issues/1440ghsaWEB
- github.com/TryGhost/node-sqlite3/issues/1449ghsaWEB
- github.com/TryGhost/node-sqlite3/security/advisories/GHSA-9qrh-qjmc-5w2pghsaWEB
- security.snyk.io/vuln/SNYK-JS-SQLITE3-2388645ghsaWEB
News mentions
0No linked articles in our index yet.