SQL_TYPE_CAST Vulnerability in DBI for Perl
CVE-2026-88815

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-88815?

The DBI for Perl before version 1.654 has a vulnerability where it improperly treats numeric values as strings within the sql_type_cast_svpv function. When casting to SQL_NUMERIC, the function passes a string pointer to grok_number without proper stringification. This oversight leads to the function attempting to access invalid memory for integer or floating-point values, resulting in a segmentation fault. This vulnerability can be exploited via the sql_type_cast function in Perl.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.