CVE-2025-70873 PUBLISHED CVSS 7.5 HIGH

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

EPSS 0.04% · 11.4th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.04%
11.4th percentile

Affected Products

VendorProductVersions
Bitnamisqlite0

Timeline

References

Open in Interactive Console →