Threat Intelligence / CVE / CVE-2026-14739
CVE-2026-14739
As of 2026-07-07, CVE-2026-14739 is a vulnerability. Threadlinqs Intelligence tracks 0 threats exploiting it.
Last updated: 2026-07-07
DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
Weaknesses (CWE)
CWE-787
References
- https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395.patch
- https://www.cve.org/CVERecord?id=CVE-2026-10879
- https://metacpan.org/release/HMBRAND/DBI-1.650/changes
Full detection coverage & IOCs for threats exploiting CVE-2026-14739 are available via the Threadlinqs MCP server (Purple tier). View plans →
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.