CVE-2026-14740Disclosure(perl / dbi)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dbi

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-08)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dbi

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-08: 2Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 207-0707-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-082
Disclosure2
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN DBI before 1.650 CVE-2026-14380: Code injection via caller-influenced Profile https://www.openwall.com/lists/oss-security/2026/07/07/16 CVE-2026-14740: Read one byte out-of-bounds in preparse when deleting an initial SQL comment https://www.openwall.com/lists/oss-security/2026/07/07/17

    Post summary

    The text announces two CVE vulnerabilities affecting Perl CPAN DBI, providing brief technical details and links to OSS‑Security mailing list discussions.

    10010188
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comme… https://www.cve.org/CVERecord?id=CVE-2026-14740 ----- Traducción: CVE-2026-14740 DBI… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-14740, noting that DBI versions prior to 1.650 for Perl contain an out‑of‑bounds read vulnerability triggered during SQL comment removal.

    0000040
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comme… https://www.cve.org/CVERecord?id=CVE-2026-14740

    Post summary

    The text discloses a new out‑of‑bounds read vulnerability in DBI Perl <=1.649, describing the affected component and mechanism, without any evidence of exploitation or mitigation.

    00000698
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appperldbi---

Explore more