
🚨 CRITICAL - Perl DBI heap overflow via extreme SQL placeholders (CVE-2026-14739) DBI for Perl before 1.650 is vulnerable to a heap overflow in its SQL statement preparse logic when handling an extreme number of placeholders. The root cause is improper bounds checking / insufficient heap allocation (heap-based buffer overflow) stemming from an incomplete prior fix for CVE-2026-10879. An attacker can exploit this by feeding an application a crafted SQL statement (directly or via user-controlled query construction) containing roughly 1.2M placeholders, triggering memory corruption during preparse without needing elevated privileges beyond reaching the vulnerable code path. Successful exploitation can lead to process crashes (DoS) and potentially remote code execution in the context of the Perl application. 👉 Affected: DBI for Perl < 1.650 | Upgrade to 1.650
Post summary
Perl DBI before version 1.650 has a heap‑overflow vulnerability triggered by an extreme number of SQL placeholders, potentially causing DoS or remote code execution, and users are advised to upgrade to version 1.650 for protection.


