Following JFrog researcher Afek Berger's discovery that several 'critical' SQLite CVEs were actually 'LLM slop,' how much should the industry fear AI-generated misinformation in security advisories?

Is 'LLM Slop' Threatening the Integrity of Security Advisories?

JFrog security researcher Afek Berger recently exposed a series of fraudulent SQLite vulnerability advisories published by a new GitHub repository, programmervuln/cveadvisory-. While the National Vulnerability Database (NVD) and CISA's ADP initially flagged these reports as critical, Berger's deep dive revealed they were likely 'LLM slop'-hallucinated vulnerabilities generated by large language models. The investigation found that the reports cited non-existent functions, incorrect line numbers, and even fabricated code patches in the SQLite source. One particularly egregious example, CVE-2026-51302, was even assigned a 10.0 critical severity score by Red Hat before being downgraded. This discovery highlights a burgeoning crisis in cybersecurity: the rise of AI-generated misinformation. As LLMs become more adept at mimicking technical documentation, they can produce convincing but entirely false security alerts. This phenomenon threatens to overwhelm security teams with 'ghost' vulnerabilities, potentially leading to wasted resources, eroded trust in official databases like NVD, and a heightened state of unnecessary alarm within the global software engineering community.

Options

  • Extremely concerned: It undermines the reliability of NVD and CISA.
  • Moderately concerned: It creates an exhausting new layer of manual verification.
  • Not concerned: Professional researchers will always be able to debunk them.
  • Unconcerned: The issue is easily managed by better automated filtering.

Pollopolis — the city of opinion