216.73.216.6

CVE-2025-71316

· Published 04/06/2026 19:16 · Modified 05/06/2026 15:56

Labels: CVE-2025-71316 2026-06-049119a7d8-5eab-497f-8521-727c672e3725CVE-2025-71316CWE-176

Essential information

Published
04/06/2026 19:16
Modified
05/06/2026 15:56
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
sqlite / sqldiff cpe:2.3:a:sqlite:sqldiff:*:*:*:*:*:*:*:*

References