VYPR
High severity7.5NVD Advisory· Published Mar 12, 2026· Updated Apr 16, 2026

CVE-2025-70873

CVE-2025-70873

Description

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Affected products

1
  • cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
    Range: <3.51.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

13