DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.
The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.
DBI version 1.650 sets a hard limit of 99,999 placeholders.
References
| Link | Resource |
|---|---|
| https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395.patch | Patch |
| https://metacpan.org/release/HMBRAND/DBI-1.650/changes | Release Notes |
| https://www.cve.org/CVERecord?id=CVE-2026-10879 | Not Applicable |
Configurations
History
No history.
Information
Published : 2026-07-07 23:16
Updated : 2026-07-10 14:41
NVD link : CVE-2026-14739
Mitre link : CVE-2026-14739
CVE.ORG link : CVE-2026-14739
JSON object : View
Products Affected
perl
- dbi
CWE
CWE-787
Out-of-bounds Write
