CVE-2026-14380Disclosure(perl / dbi)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch perl dbi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95CWE-470

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dbi

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
dbi

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-20: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-20: 107-0807-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-201
Patch1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN DBI before 1.650 CVE-2026-14380: Code injection via caller-influenced Profile https://www.openwall.com/lists/oss-security/2026/07/07/16 CVE-2026-14740: Read one byte out-of-bounds in preparse when deleting an initial SQL comment https://www.openwall.com/lists/oss-security/2026/07/07/17

    Post summary

    The post lists two CVE identifiers affecting Perl CPAN DBI with concise technical notes, but offers no proof‑of‑concept, exploit code, patches, or evidence of active exploitation.

    10010188
    4.7K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ Red Hat Enterprise Linux 10 alert: CVE-2026-14380 (CVSS 8.8) Attackers could execute arbitrary code. Apply the vendor-recommended mitigation. https://vulnipulse.com/advisories/linux-cve-2026-14380 #Linux #RedHatEnterpriseLinux10 #RCE #CyberSecurity #CVE

    Post summary

    Red Hat’s advisory for CVE‑2026‑14380 with CVSS 8.8 highlights arbitrary code execution risk and urges users to apply the vendor‑recommended mitigation.

    0000047
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperldbi---

Explore more