Vulnerability Description
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
- https://metacpan.org/release/HMBRAND/DBI-1.651/changes
- http://www.openwall.com/lists/oss-security/2026/07/14/13
FAQ
What is CVE-2026-60082?
CVE-2026-60082 is a vulnerability with a CVSS score of 9.1 (CRITICAL). DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper w...
How severe is CVE-2026-60082?
CVE-2026-60082 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-60082?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.