Executive brief
DBI is a widely-used Perl database interface library that enables applications to connect to and query databases. A vulnerability allows arbitrary code execution through a crafted Profile attribute, potentially letting an attacker run malicious code on systems running affected Perl applications that use DBI.
Technical details
DBI contains an incomplete fix for CVE-2026-14380, leaving a code execution vulnerability reachable via a caller-influenced Profile attribute. The vulnerability allows arbitrary code execution without requiring authentication or special privileges, though the exact attack preconditions (such as whether user interaction or database connection setup is required) are not detailed in the advisory. An attacker can exploit this to execute arbitrary code in the context of the application using DBI. A patch is available in Red Hat Enterprise Linux 10 and 10.2 via perl-DBI version 1.643-26.el10_2.4 and later.
Affected products
- CPAN DBI prior to 1.643-26.el10_2.4 (Red Hat builds)
Timeline
- 2026-08-11: disclosed
- 2026-09-09: advisory
- 2026-09-09: patched