Junglewise Threat Intelligence

CVE-2026-15043: HMBRAND DBI::SQL::Nano inverted comparison operators in WHERE predicates

CVE-2026-15043 · Severity: info · CVSS 7.5 · Published 2026-07-14

Executive brief

A logic error exists in a common database tool for the Perl programming language used to handle file-based data like CSV or DBM files. When an application uses this tool to filter data based on text ranges (such as 'greater than or equal to'), it may return the exact opposite of the requested information. This could allow unauthorized users to view sensitive records that should have been filtered out by security rules.

Technical details

A logic error in the `is_matched` method of `DBI::SQL::Nano.pm` causes the `<=` operator to be evaluated using Perl's `ge` (greater than or equal) operator and the `>=` operator to be evaluated using `le` (less than or equal) for non-numeric string comparisons. This component serves as the default SQL engine for file-backed DBI drivers (such as DBD::File, DBD::DBM, and CSV) when `SQL::Statement` is unavailable. An attacker can exploit this if an application uses these operators in `WHERE` clauses to enforce authorization or data partitioning, leading to the retrieval of the complementary (incorrect) set of rows. The vulnerability also includes issues where the `IS` operator ignores its right-hand operand and primary key lookups may incorrectly match using regex. The issue is resolved in version 1.651.

Affected products

  • HMBRAND DBI::SQL::Nano 1.42 to 1.650

Timeline

  • 2026-07-10: patched: Fix committed to repository
  • 2026-07-14: disclosed: Security advisory published via GitHub and CPANSec
  • 2026-07-14: advisory: NVD record published

References