CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Published Jul 7, 2026
·Updated
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile
Affected Software
3 affected componentsFixes available
DBI DBI<1.650
Perl DBI<1.650
Microsoft azl3 perl-DBI 1.643-5<1.650-1
1.650-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.650-1 - Upgrade
Upgrade
Perl DBIto a version that resolves this vulnerability.Fixed in 1.650
Event History
Jul 7, 2026
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
RemedyDescriptionWeakness
Data Sourced
via Red Hat·11:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 11, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-14380?
CVE-2026-14380 has a risk score of 83, indicating it's a high-severity vulnerability.
2
What does CVE-2026-14380 affect?
CVE-2026-14380 affects DBI versions prior to 1.650 for Perl, which is vulnerable to code injection.
3
How do I fix CVE-2026-14380?
To fix CVE-2026-14380, upgrade your DBI to version 1.650 or later.
4
What kind of vulnerability is CVE-2026-14380?
CVE-2026-14380 is classified as a code injection vulnerability.
5
What is the impact of CVE-2026-14380 on applications?
The impact of CVE-2026-14380 can include unauthorized execution of code due to unvalidated package names being interpolated in eval.