{"id":"AZL-92202","summary":"CVE-2026-14739 affecting package perl-DBI for versions less than 1.650-1","details":"DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders.\n\nThe fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders.\n\nDBI version 1.650 sets a hard limit of 99,999 placeholders.","modified":"2026-08-28T17:48:06.704172252Z","published":"2026-07-07T23:16:54Z","upstream":["CVE-2026-14739"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14739"}],"affected":[{"package":{"name":"perl-DBI","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-DBI"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.650-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92202.json"}}],"schema_version":"1.9.0"}