CVE-2026-60082
CRITICALDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
Title source: cnaDescription
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
Release Notes release-notes
https://metacpan.org/release/HMBRAND/DBI-1.651/changes
Scores
CVSS v3
9.1
EPSS
0.0039
EPSS Percentile
31.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (1)
HMBRAND/DBI
< 1.651
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026