The Perl DBI project released a series of updates that fixed multiple security flaws across DBI and related components including DBI::SQL::Nano, DBD::File, and DBI::ProfileData. The changelog for versions 1.648, 1.650, and 1.651 lists fixes for CVE-2026-9698, CVE-2026-10879, CVE-2026-14380, CVE-2026-14739, CVE-2026-14740, CVE-2026-15043, CVE-2026-15392, CVE-2026-60081, and CVE-2026-60082, reflecting a broad hardening effort across the database interface stack.
The patched issues include code injection, out-of-bounds reads, buffer and stack overflows, path traversal or symlink problems, and limits around placeholder parsing. One of the referenced weakness classes is CWE-134, Use of Externally-Controlled Format String, underscoring the memory-safety and input-handling risks addressed in the releases. Organizations using Perl applications that depend on DBI or its file- and SQL-related modules should prioritize upgrading to the latest fixed versions and review exposed components for unsafe input handling and file access patterns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The changelog reports that DBI version 1.651 fixed CVE-2026-15043, CVE-2026-15392, CVE-2026-60082, and CVE-2026-60081. These fixes covered vulnerabilities including issues in DBI and related components such as DBI::SQL::Nano, DBD::File, and DBI::ProfileData.
According to the changelog, DBI version 1.650 fixed CVE-2026-14739, CVE-2026-14740, and CVE-2026-14380. The synopsis indicates this release occurred during June and July 2026.
The DBI project changelog states that version 1.648 fixed CVE-2026-9698 and CVE-2026-10879 as part of security hardening work across the codebase. The synopsis places this release in June 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.