Critical severity9.8NVD Advisory· Published Jul 7, 2026· Updated Jul 10, 2026
CVE-2026-14739
CVE-2026-14739
Description
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.
The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.
DBI version 1.650 sets a hard limit of 99,999 placeholders.
Affected products
4cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*range: <1.650
- (no CPE)range: <1.650
- osv-coords2 versions
< 1.650.0-1.1+ 1 more
- (no CPE)range: < 1.650.0-1.1
- (no CPE)range: < 1.643-26.el10_2.3
Patches
Vulnerability mechanics
References
3- github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395.patchnvdPatch
- metacpan.org/release/HMBRAND/DBI-1.650/changesnvdRelease Notes
- www.cve.org/CVERecordnvdNot Applicable
News mentions
1- Perl Modules: Seven Vulnerabilities Disclosed, Affecting DBI, Crypt::DSA, and MoreVypr Intelligence · Jul 8, 2026