CVE-2026-14740
Critical · CVSS 9.1DBI (Perl) — Out-of-bounds read (CWE-125) in SQL comment parsing
- CVSS
- 9.1
- nvd
- EPSS
- 0.41%
- 33th pct
- KEV
- No
- Class
- oss containerizable
- CWE-125
Description
DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.
Search profile — drives PoC discovery
Symbols preparseDBIfc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01GHSA-35f4-f8m9-w8xgDBI-1.650
Keywords CVE-2026-14740DBI Perl out-of-bounds readDBI preparse SQL commentDBI 1.650GHSA-35f4-f8m9-w8xgperl5-dbi preparse patchDBI SQL comment normalization vulnerability
Versions: < 1.650
References
Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z