Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-88816— DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName

Quick assessment

Affected
CVE-2026-88816
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Perl 的 DBI 模块 1.654 版本之前, 属性在处理数值时会错误地将其视为字符串。 方法直接使用 属性的字符串指针作为哈希键名,而未先对其进行字符串化(stringify)处理。当 被设置为整数(IV)或浮点数(NV)值时,其对应的字符串指针是无效的,因此尝试读取键名将触发段错误(segmentation fault)。 该问题可通过以下代码触发:

AI Predicted 5.9 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 1

VendorProduct Version RangeStatus
None None < 1.654 affected

I. Basic Information for CVE-2026-88816

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName
Source: CVE Program / CVE List V5
Vulnerability Description
DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault. This can be triggered with the following code: my $dbh = DBI->connect( "dbi:ExampleP:", "", "", { RaiseError => 0, PrintError => 0 } ); $dbh->{FetchHashKeyName} = 42; my $sth = $dbh->prepare("select mode, size, name from ."); $sth->execute; $sth->fetchrow_hashref;
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 1.654 -

II. Public POCs for CVE-2026-88816

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88816

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-88816 (1)

Vendor Advisories for CVE-2026-88816 (1)

Other References for CVE-2026-88816 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88816

No comments yet


Leave a comment