Junglewise Threat Intelligence

CVE-2026-60081: Perl DBI memory exhaustion in DBI::ProfileData parser

CVE-2026-60081 · Severity: info · CVSS 3.3 · Published 2026-07-14

Technologies: Perl DBI Team DBI. Vendors: Perl DBI Team.

Executive brief

The DBI::ProfileData component in the Perl DBI library, which is used for analyzing database performance profiles, contains a flaw in how it processes profile dump files. An attacker can provide a specially crafted, small profile file that causes the parser to consume excessive amounts of system memory. This can lead to a denial-of-service condition where the application or server crashes or becomes unresponsive.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in DBI::ProfileData's profile parser. The parser reads 'path index' values from profile dump files and uses them to set the size of an internal array (@path) without upper-bound validation. By providing a large index value (e.g., +10000000), an attacker can trigger a memory amplification effect where a small input file causes the allocation of a massive sparse array, leading to a denial-of-service (DoS) via memory exhaustion. This affects any workflow where the parser processes untrusted profile data, such as in CI/CD pipelines or observability tools. The issue is fixed in version 1.651 by introducing a $MAX_PATH_DEPTH limit.

Affected products

  • Perl DBI Team DBI before 1.651

Timeline

  • 2026-07-10: other: Fix developed by maintainers
  • 2026-07-14: patched: Version 1.651 released
  • 2026-07-14: advisory: GHSA-ww49-w4mv-jrr4 published

References

Related threats