Executive brief
The DBI::ProfileData component in the Perl DBI library, which is used for analyzing database performance profiles, contains a flaw in how it processes profile dump files. An attacker can provide a specially crafted, small profile file that causes the parser to consume excessive amounts of system memory. This can lead to a denial-of-service condition where the application or server crashes or becomes unresponsive.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in DBI::ProfileData's profile parser. The parser reads 'path index' values from profile dump files and uses them to set the size of an internal array (@path) without upper-bound validation. By providing a large index value (e.g., +10000000), an attacker can trigger a memory amplification effect where a small input file causes the allocation of a massive sparse array, leading to a denial-of-service (DoS) via memory exhaustion. This affects any workflow where the parser processes untrusted profile data, such as in CI/CD pipelines or observability tools. The issue is fixed in version 1.651 by introducing a $MAX_PATH_DEPTH limit.
Affected products
- Perl DBI Team DBI before 1.651
Timeline
- 2026-07-10: other: Fix developed by maintainers
- 2026-07-14: patched: Version 1.651 released
- 2026-07-14: advisory: GHSA-ww49-w4mv-jrr4 published