THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14380 (HIGH 8.8) — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation

[NVD] CVE-2026-14380 (HIGH 8.8) — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation

lownvdPublished 2026-07-07

CVE-2026-14380 CVSS: 8.8 HIGH Published: 2026-07-07T23:16:53.963

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.

When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name.

Any caller-influenced value tha

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14380