DBI::ProfileData versions before 1.651 for Perl do not limit the path index.
The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-dbi | Jul 28, 2026 | Jul 14, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-DBI-debuginfoUpgrade perl-DBI | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-DBI-testsUpgrade perl-DBI-debuginfoUpgrade perl-DBI-debugsourceUpgrade perl-DBI | Aug 10, 2026 | Jul 14, 2026 |
| Debian | — | Upgrade libdbi-perl | Aug 30, 2026 | Aug 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 20, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub