Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-15043: DBI::SQL::Nano for Perl has incorrect SQL operator behavior

CVE-2026-15043 · published 2 months ago
Summary

Old versions of DBI::SQL::Nano for Perl incorrectly handle certain SQL operators, which can lead to incorrect results when filtering data. This affects applications that rely on WHERE clauses to control access to file-backed data. To fix this, update DBI::SQL::Nano to version 1.651 or later.

What to do
  • Update bellsoft perl-dbi to version 1.651-r0.
  • Update hmbrand dbi::sql::nano to version 1.651 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian libdbi-perl All versions
Debian:12 debian libdbi-perl All versions
Debian:13 debian libdbi-perl All versions
Debian:14 debian libdbi-perl All versions
Ubuntu:26.04:LTS canonical libdbi-perl All versions
– hmbrand dbi::sql::nano < 1.651
Ubuntu:Pro:14.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:16.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:18.04:LTS canonical libdbi-perl All versions
Ubuntu:Pro:20.04:LTS canonical libdbi-perl All versions
Ubuntu:22.04:LTS canonical libdbi-perl All versions
Ubuntu:24.04:LTS canonical libdbi-perl All versions
Alpaquita:23 bellsoft perl-dbi >= 1.643-r4, < 1.651-r0
Fix: upgrade to 1.651-r0
Alpaquita:25 bellsoft perl-dbi >= 1.647-r0, < 1.651-r0
Fix: upgrade to 1.651-r0
Alpaquita:stream bellsoft perl-dbi >= 1.643-r3, < 1.651-r0
Fix: upgrade to 1.651-r0
Original advisory text
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.

DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.

SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.

The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.
Severity
9.8 Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-480Use of Incorrect Operator
Timeline
Published14 Jul 2026
Updated27 Sep 2026
First seen14 Jul 2026
Track software like this
Free during beta