CVE-2026-60082

CRITICAL

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

Title source: cna
STIX 2.1

Description

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
HMBRAND/DBI < 1.651
Published Jul 14, 2026
Tracked Since Jul 14, 2026