Numeric Value Handling Vulnerability in DBI for Perl
CVE-2026-88816

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-88816?

The DBI module for Perl has a vulnerability in the handling of the FetchHashKeyName attribute, which leads to improperly managed numeric values. In versions prior to 1.654, these values are treated as strings without proper stringification, causing instability in the execution of the fetchrow_hashref method. If a number is incorrectly assigned to FetchHashKeyName, it can lead to a segmentation fault, posing significant risks to application stability. This issue can be triggered with specific code configurations, illustrating the importance of staying updated with the latest versions to avoid such pitfalls.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.