Arbitrary Module Loading Vulnerability in DBI by HMBRAND
CVE-2026-78030

Currently unrated

Key Information:

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-78030?

The DBI module versions prior to 1.653 for Perl are susceptible to an arbitrary module loading vulnerability. This issue arises from the unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM, which allow an attacker to influence the connection attributes without proper checks. When these attributes are provided through untrusted channels, it enables the loading of unintended modules, posing a significant security risk. For instance, an attacker could manipulate a Data Source Name (DSN) to point to a malicious module, executing arbitrary code within the application's context. It is crucial for users of affected DBI versions to upgrade to avoid potential exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.