CVE-2026-9698: Perl Dbi

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.

Affected products

  • Perl Dbi: before 1.648 (fixed in 1.648)

Published 2026-06-09. Last modified 2026-09-03.