Perl Foundation: Three Vulnerabilities in DBI and XS::Parse::Infix Disclosed Together
Perl Foundation's DBI and XS::Parse::Infix modules impacted by three vulnerabilities related to improper type handling and reference checks.

Key findings
- Three vulnerabilities disclosed in Perl's DBI and XS::Parse::Infix modules on September 28, 2026.
- DBI vulnerabilities (CVE-2026-88816, CVE-2026-88815) stem from improper numeric-to-string type handling.
- XS::Parse::Infix vulnerability (CVE-2026-85644) involves incorrect array reference checking.
- Affected DBI versions are prior to 1.654; affected XS::Parse::Infix versions are 0.40 through 0.49.
- Updates to DBI 1.654+ and XS::Parse::Infix 0.49+ are recommended.
The Perl Foundation's DBI and XS::Parse::Infix modules are affected by a batch of three vulnerabilities disclosed on September 28, 2026. These issues, affecting DBI versions prior to 1.654 and XS::Parse::Infix versions from 0.40 through 0.49, stem from improper handling of numeric values and array references, potentially leading to security risks.
Two of the vulnerabilities, CVE-2026-88816 and CVE-2026-88815, impact the DBI module. Both arise from incorrect treatment of numeric values as strings within key name fetching and type casting functions, respectively. Specifically, FetchHashKeyName and sql_type_cast_svpv pass string pointers of numeric values without proper stringification. This can lead to issues when these values are used as keys or cast to numeric types, as the underlying string pointer may be invalid for integer (IV) or floating-point (NV) values.
The third vulnerability, CVE-2026-85644, affects the XS::Parse::Infix module. This issue involves the module treating a number as an array reference due to a flawed check for array references. The wrapper function generated for list-associative infix operators uses SvRV() instead of SvROK() to test if arguments are array references. Since SvRV() reads a union slot that may not hold a valid reference, this can lead to incorrect behavior when processing such operators.
The implications of these vulnerabilities are not fully detailed in the provided information, but improper handling of data types and references can often lead to unexpected application behavior, denial-of-service conditions, or, in some cases, more severe security exploits such as code injection or information disclosure, depending on how the affected functions are utilized within larger Perl applications.
As of the disclosure date, DBI versions prior to 1.654 and XS::Parse::Infix versions 0.40 through 0.49 are affected. Users are advised to update to DBI version 1.654 or later to mitigate CVE-2026-88816 and CVE-2026-88815. For CVE-2026-85644, updating XS::Parse::Infix to a version beyond 0.49 is recommended.
These vulnerabilities highlight the importance of careful type handling and reference checking in Perl modules. Developers relying on DBI and XS::Parse::Infix should ensure they are using updated versions to protect their applications from potential security risks stemming from these disclosed flaws. Further investigation into specific exploit scenarios may be warranted based on the integration of these modules within individual projects.