{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.654"
              }
            ],
            "source": [
              "DESCRIPTION",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4e9aa3345770a3afd3cd37b305f15c97e3cd70bc"
            },
            {
              "fixed": "70962570212dc60a5428098cf2a0462ad5945851"
            }
          ],
          "repo": "https://github.com/perl5-dbi/dbi",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-f4qx-mr9m-q2hq"
  ],
  "database_specific": {
    "cna_assigner": "CPANSec",
    "cwe_ids": [
      "CWE-843"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88816.json"
  },
  "details": "DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName.\n\nfetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When FetchHashKeyName has been set to an integer (IV) or floating-point (NV) value, that pointer is invalid, so reading the key name triggers a segmentation fault.\n\nThis can be triggered with the following code:\n\n   my $dbh = DBI-\u003econnect( \"dbi:ExampleP:\", \"\", \"\",\n       { RaiseError =\u003e 0, PrintError =\u003e 0 } );\n   $dbh-\u003e{FetchHashKeyName} = 42;\n\n   my $sth = $dbh-\u003eprepare(\"select mode, size, name from .\");\n   $sth-\u003eexecute;\n   $sth-\u003efetchrow_hashref;",
  "id": "CVE-2026-88816",
  "modified": "2026-10-01T03:31:06.228008526Z",
  "published": "2026-09-28T16:04:40.458Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/09/28/13"
    },
    {
      "type": "WEB",
      "url": "https://cpan.org/modules"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88816.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/perl5-dbi/dbi/security/advisories/GHSA-f4qx-mr9m-q2hq"
    },
    {
      "type": "ADVISORY",
      "url": "https://metacpan.org/release/HMBRAND/DBI-1.654/changes"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88816"
    },
    {
      "type": "FIX",
      "url": "https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851.patch"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/perl5-dbi/dbi"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName"
}