CVE-2026-14739Disclosure(perl / dbi)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch perl dbi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dbi

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-08)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dbi

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-08: 2Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 207-0707-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-082
Disclosure2
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Perl DBI heap overflow via extreme SQL placeholders (CVE-2026-14739) DBI for Perl before 1.650 is vulnerable to a heap overflow in its SQL statement preparse logic when handling an extreme number of placeholders. The root cause is improper bounds checking / insufficient heap allocation (heap-based buffer overflow) stemming from an incomplete prior fix for CVE-2026-10879. An attacker can exploit this by feeding an application a crafted SQL statement (directly or via user-controlled query construction) containing roughly 1.2M placeholders, triggering memory corruption during preparse without needing elevated privileges beyond reaching the vulnerable code path. Successful exploitation can lead to process crashes (DoS) and potentially remote code execution in the context of the Perl application. 👉 Affected: DBI for Perl < 1.650 | Upgrade to 1.650

    Post summary

    Perl DBI before version 1.650 has a heap‑overflow vulnerability triggered by an extreme number of SQL placeholders, potentially causing DoS or remote code execution, and users are advised to upgrade to version 1.650 for protection.

    00000127
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not all… https://www.cve.org/CVERecord?id=CVE-2026-14739 ----- Traducción: CVE-2026-14739 DBI… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑14739, detailing a heap‑overflow vulnerability in Perl/DBI during SQL preparsing, without mentioning PoC, exploit tools, active attacks, or patches.

    0000038
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not all… https://www.cve.org/CVERecord?id=CVE-2026-14739

    Post summary

    CVE‑2026‑14739 is a heap overflow in Perl’s DBI library (versions <1.650) caused by excessive placeholders; no PoC, exploit code, patch, or active exploitation is mentioned.

    000001.1K
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperldbi---

Explore more