{"id":"CVE-2026-88815","title":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.\n\nWhen casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it …","summary":"DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.\n\nWhen casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it …","severity":"none","cwe":["CWE-843"],"product":"DBI","affected":["DBI < 1.654"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T17:17:52.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88815","references":[{"url":"https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702.patch","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/perl5-dbi/dbi/security/advisories/GHSA-c8vq-w3wr-6979","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/HMBRAND/DBI-1.654/changes","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T17:16:27.817Z","slug":"CVE-2026-88815","body":"## Overview\n\nDBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv.\n\nWhen casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without stringifying it first. An integer (IV) or floating-point (NV) value has no valid string pointer, so grok_number reads from an invalid address, triggering a segmentation fault.\n\nThis is reachable in Perl using the sql_type_cast function:\n\n  my $num = 42;\n  DBI::sql_type_cast( $num, DBI::SQL_NUMERIC, 0 );\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}