CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-14740

Critical · CVSS 9.1

DBI (Perl) — Out-of-bounds read (CWE-125) in SQL comment parsing

CVSS
9.1
nvd
EPSS
0.41%
33th pct
KEV
No
Class
oss containerizable
CWE-125

Description

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.

Search profile — drives PoC discovery

Symbols preparseDBIfc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01GHSA-35f4-f8m9-w8xgDBI-1.650
Keywords CVE-2026-14740DBI Perl out-of-bounds readDBI preparse SQL commentDBI 1.650GHSA-35f4-f8m9-w8xgperl5-dbi preparse patchDBI SQL comment normalization vulnerability
Versions: < 1.650

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z