In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated… (CVE-2025-29087)
SQLite versions 3.44.0 through 3.49.0 before 3.49.1 contain a vulnerability in the concat_ws() SQL function where memory can be written beyond the end of a malloc-allocated buffer. This occurs due to an integer overflow when the separator argument is attacker-controlled and very large, causing insufficient memory allocation.
AI Analysis
Technical Summary
In SQLite versions 3.44.0 through 3.49.0 prior to 3.49.1, the concat_ws() SQL function has a vulnerability that allows memory corruption. Specifically, if the separator argument is controlled by an attacker and is a large string (e.g., 2MB or more), an integer overflow happens during the calculation of the result buffer size. This leads to malloc allocating less memory than required, causing writes beyond the allocated buffer boundary.
Potential Impact
This vulnerability can lead to memory corruption, which may cause application crashes or potentially allow an attacker to execute arbitrary code depending on the context in which SQLite is used. The severity is rated high due to the risk of memory corruption from attacker-controlled input.
Mitigation Recommendations
A patch is available in SQLite version 3.49.1 that fixes this vulnerability. Users should upgrade to version 3.49.1 or later to remediate this issue.
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated… (CVE-2025-29087)
Description
SQLite versions 3.44.0 through 3.49.0 before 3.49.1 contain a vulnerability in the concat_ws() SQL function where memory can be written beyond the end of a malloc-allocated buffer. This occurs due to an integer overflow when the separator argument is attacker-controlled and very large, causing insufficient memory allocation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In SQLite versions 3.44.0 through 3.49.0 prior to 3.49.1, the concat_ws() SQL function has a vulnerability that allows memory corruption. Specifically, if the separator argument is controlled by an attacker and is a large string (e.g., 2MB or more), an integer overflow happens during the calculation of the result buffer size. This leads to malloc allocating less memory than required, causing writes beyond the allocated buffer boundary.
Potential Impact
This vulnerability can lead to memory corruption, which may cause application crashes or potentially allow an attacker to execute arbitrary code depending on the context in which SQLite is used. The severity is rated high due to the risk of memory corruption from attacker-controlled input.
Mitigation Recommendations
A patch is available in SQLite version 3.49.1 that fixes this vulnerability. Users should upgrade to version 3.49.1 or later to remediate this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-sqlite-2025-29087
- Osv Schema Version
- 1.5.0
- Aliases
- ["CVE-2025-29087"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- High
Threat ID: 6aa005c1acd9273b49ab5bb3
Added to database: 09/08/2026, 12:55:29 UTC
Last enriched: 09/08/2026, 13:17:19 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.