THREAT OPS › Threat News › [NVD] CVE-2026-14380 (HIGH 8.8) — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.
When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation
[NVD] CVE-2026-14380 (HIGH 8.8) — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation
CVE-2026-14380 CVSS: 8.8 HIGH Published: 2026-07-07T23:16:53.963
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile.
When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name.
Any caller-influenced value tha
Indicators of compromise
- CVE-2026-14380cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14380