There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanSQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite affects SQLitePCLRaw.lib.e_sqlite3 (nuget), SQLitePCLRaw.lib.e_sqlite3.android (nuget), SQLitePCLRaw.lib.e_sqlite3.ios (nuget). Severity is high. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
AI coding agents often install or upgrade packages automatically in nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| SQLitePCLRaw.lib.e_sqlite3nuget | <=2.1.11 | Not reported |
| SQLitePCLRaw.lib.e_sqlite3.android |
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanSQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite affects SQLitePCLRaw.lib.e_sqlite3 (nuget), SQLitePCLRaw.lib.e_sqlite3.android (nuget), SQLitePCLRaw.lib.e_sqlite3.ios (nuget). Severity is high. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
AI coding agents often install or upgrade packages automatically in nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| SQLitePCLRaw.lib.e_sqlite3nuget | <=2.1.11 | Not reported |
| SQLitePCLRaw.lib.e_sqlite3.android |
| <=2.1.11 |
| Not reported |
| SQLitePCLRaw.lib.e_sqlite3.iosnuget | <=2.1.11 | Not reported |
|---|
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <=2.1.11 |
| Not reported |
| SQLitePCLRaw.lib.e_sqlite3.iosnuget | <=2.1.11 | Not reported |
|---|
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard