CVE-2026-14739
Critical · CVSS 9.8Perl DBI — heap buffer overflow via SQL placeholder preparsing
- CVSS
- 9.8
- nvd
- EPSS
- 0.40%
- 32th pct
- KEV
- No
- Class
- oss containerizable
- CWE-787
Description
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
Search profile — drives PoC discovery
Symbols preparsingplaceholdersDBIDBDsql_type_castparse_paramsDBIcDBDheap overflow999991200000
Keywords CVE-2026-14739CVE-2026-10879Perl DBI heap overflowDBI placeholder overflowDBI 1.650DBI before 1.650SQL placeholder preparsing heapCWE-787 DBI Perlperl5-dbi heap overflow PoCDBI placeholder limit bypass
Versions: < 1.650
References
Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z