Vulnerability Description
UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tokuhirom | Unqlite | < 0.07 |
References
- https://metacpan.org/release/TOKUHIROM/UnQLite-0.07/source/ChangesRelease Notes
- https://unqlite.symisc.net/Product
- https://www.cve.org/CVERecord?id=CVE-2025-3791Third Party Advisory
FAQ
What is CVE-2026-3257?
CVE-2026-3257 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a ver...
How severe is CVE-2026-3257?
CVE-2026-3257 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-3257?
Check the references section above for vendor advisories and patch information. Affected products include: Tokuhirom Unqlite.