Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-35737

32
FAUCET Score

CVE-2022-35737 describes an array-bounds overflow vulnerability in SQLite versions 1.0.12 through 3.39.x before 3.39.2, which can occur when processing string arguments of billions of bytes via its C API. This flaw impacts various products, including NetApp, Splunk, and other SQLite implementations. With a CVSS score of 7.5 (HIGH), it presents a high availability impact without requiring user interaction or privileges, though it has a low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.12, < 3.39.2CPE matchmatch criteria
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
>= 8.2.0, < 8.2.12CPE matchmatch criteria
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.6CPE matchmatch criteria
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
9.1.0CPE matchmatch criteria
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
17.98%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1798 is in the 95th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for 32-bit SystemsFixed in: 10.0.19045.3930
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for 32-bit SystemsFixed in: 10.0.19044.3930
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 10.0.19044.3930
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for x64-based SystemsFixed in: 10.0.19044.3930
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for x64-based SystemsFixed in: 10.0.19045.3930
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 10.0.19045.3930
View patch
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 3.34.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 3.34.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.39.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.39.2-1
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit SystemsFixed in: 10.0.17763.5329
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based SystemsFixed in: 10.0.17763.5329
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for ARM64-based SystemsFixed in: 10.0.17763.5329
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.5329
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.5329
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.2227
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.2227
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: sqlite-0:3.26.0-16.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: sqlite-0:3.34.1-6.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: sqlite-0:3.26.0-17.el8_7
View patch
rustpatch availablevia ghsa
Product: libsqlite3-sysFixed in: 0.25.1
zimbrapatch availablevia llm_extracted
Fixed in: 8.2.12, 9.0.6, 9.1.1

Vendor Advisories (6)

microsoft2024-Jan/CVE-2022-35737

MITRE: CVE-2022-35737 SQLite allows an array-bounds overflow

Jan 9, 2024
zimbrallm-zimbra-9542faa91a6d6884HIGH

August Third Party Package Updates in Splunk Universal Forwarder

Aug 30, 2023
bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
microsoft2022-Aug/CVE-2022-35737

CVE-2022-35737

Aug 9, 2022
rustGHSA-jw36-hf63-69r9high

`libsqlite3-sys` via C SQLite improperly validates array index

Aug 4, 2022
redhatCVE-2022-35737Moderate

sqlite: an array-bounds overflow if billions of bytes are used in a string argument to a C API

Jul 22, 2022

References

blog.trailofbits.com / 2022/10/25/sqlite-vulnerability-july-2022-library-api
ExploitThird Party Advisory
kb.cert.org / vuls/id/720344
Broken LinkThird Party AdvisoryUS Government Resource
security.gentoo.org / glsa/202210-40
Third Party Advisory
security.netapp.com / advisory/ntap-20220915-0009
Third Party Advisory
sqlite.org / releaselog/3_39_2.html
Release NotesVendor Advisory
sqlite.org / cves.html
Vendor Advisory