DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an application can trigger a buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
| perl | dbi | 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| cpanel | cpanel/whm | cert_advisory | 90% |
Updated severity to CRITICAL, added affected version 1.647, and included new CVE ID CVE-2026-9698.
Updated severity to HIGH, added CVSS estimate of 7.5, and marked exploit as available and actively exploited.
Initial creation