Vulnerability Description
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perl | Dbi | < 1.650 |
Related Weaknesses (CWE)
References
- https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395Patch
- https://metacpan.org/release/HMBRAND/DBI-1.650/changesRelease Notes
- https://www.cve.org/CVERecord?id=CVE-2026-10879Not Applicable
FAQ
What is CVE-2026-14739?
CVE-2026-14739 is a vulnerability with a CVSS score of 9.8 (CRITICAL). DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle appr...
How severe is CVE-2026-14739?
CVE-2026-14739 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-14739?
Check the references section above for vendor advisories and patch information. Affected products include: Perl Dbi.