CVE-2026-14380
CVE-2026-14380 is a high-severity vulnerability in Perl Dbi with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-95.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- EPSS exploit prediction: 0% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-95
- Affected product: Perl Dbi
- Published:
- Last modified:
Description
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
Frequently asked questions
- What is CVE-2026-14380?
- DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host.
- How severe is CVE-2026-14380?
- CVE-2026-14380 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-14380 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-14380?
- CVE-2026-14380 affects Perl Dbi. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-14380?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-14380 published?
- CVE-2026-14380 was published on 2026-07-07 and last updated on 2026-08-31.
References
- https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259.patch
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
- https://metacpan.org/release/HMBRAND/DBI-1.650/changes
- http://www.openwall.com/lists/oss-security/2026/07/07/16
Affected products (1)
- cpe:2.3:a:perl:dbi:*:*:*:*:*:*:*:*
More vulnerabilities in Perl Dbi
- CVE-2026-14739 — Critical (CVSS 9.8): DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of…
- CVE-2026-9698 — Critical (CVSS 9.8): DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when…
- CVE-2026-10879 — Critical (CVSS 9.8): DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The…
- CVE-2026-14740 — Critical (CVSS 9.1): DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The…
- CVE-2014-10402 — Medium (CVSS 6.1): An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other…
- CVE-2014-10401 — Medium (CVSS 6.1): An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other…
Other CWE-95 (Eval Injection) vulnerabilities
- CVE-2026-61539 — Critical (CVSS 10.0): Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference…
- CVE-2026-44643 — Critical (CVSS 10.0): Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an…
- CVE-2025-68271 — Critical (CVSS 10.0): OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.…
- CVE-2013-10070 — Critical (CVSS 10.0): PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names…
- CVE-2022-36010 — Critical (CVSS 10.0): This library allows strings to be parsed as functions and stored as a specialized component,…
- CVE-2026-57149 — Critical (CVSS 9.9): plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of…