Sqlite also has never had a severe CVE, from the parent's link:
> All historical vulnerabilities reported against SQLite require at least one of these preconditions:
> The attacker can submit and run arbitrary SQL statements.
> The attacker can submit a maliciously crafted database file to the application that the application will then open and query.
The OP's vulnerability requires passing an insanely long string to a C api, which isn't something you'd expect to be secure.