CVE-2026-14739
EUVD-2026-4212407.07.2026, 23:16
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| perl | dbi | 𝑥 < 1.650 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| perl-DBI |
| ||||
| perl-DBI-debuginfo |
| ||||
| perl-DBI-debugsource |
| ||||
| perl-DBI-tests |
|
Common Weakness Enumeration