DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.
The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.
DBI version 1.650 sets a hard limit of 99,999 placeholders.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-DBI | Aug 5, 2026 | Aug 3, 2026 |
| Alpine Linux | — | Upgrade perl-dbi | Jul 28, 2026 | Jul 7, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-DBIUpgrade perl-DBI-debuginfo | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-DBI-testsUpgrade perl-DBI-debuginfoUpgrade perl-DBIUpgrade perl-DBI-debugsource | Jul 21, 2026 | Jul 7, 2026 |
| Debian | — | Upgrade libdbi-perl | Aug 30, 2026 | Aug 30, 2026 |
| Redhat_linux | — | No solution existsUpgrade perl-DBIUpgrade perl-DBI-debugsourceUpgrade perl-DBI-debuginfo | Jul 17, 2026 | Jul 7, 2026 |
| Rocky_linux | — | Upgrade perl-DBI-debugsourceUpgrade perl-DBI-debuginfoUpgrade perl-DBI | Aug 6, 2026 | Aug 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub