Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-15043: DBI::SQL::Nano for Perl has incorrect SQL operator behavior
CVE-2026-15043 · published 2 months ago
Summary
Old versions of DBI::SQL::Nano for Perl incorrectly handle certain SQL operators, which can lead to incorrect results when filtering data. This affects applications that rely on WHERE clauses to control access to file-backed data. To fix this, update DBI::SQL::Nano to version 1.651 or later.
What to do
- Update bellsoft perl-dbi to version 1.651-r0.
- Update hmbrand dbi::sql::nano to version 1.651 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | libdbi-perl | All versions |
| Debian:12 | debian | libdbi-perl | All versions |
| Debian:13 | debian | libdbi-perl | All versions |
| Debian:14 | debian | libdbi-perl | All versions |
| Ubuntu:26.04:LTS | canonical | libdbi-perl | All versions |
| – | hmbrand | dbi::sql::nano | < 1.651 |
| Ubuntu:Pro:14.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:22.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:24.04:LTS | canonical | libdbi-perl | All versions |
| Alpaquita:23 | bellsoft | perl-dbi |
>= 1.643-r4, < 1.651-r0 Fix: upgrade to 1.651-r0
|
| Alpaquita:25 | bellsoft | perl-dbi |
>= 1.647-r0, < 1.651-r0 Fix: upgrade to 1.651-r0
|
| Alpaquita:stream | bellsoft | perl-dbi |
>= 1.643-r3, < 1.651-r0 Fix: upgrade to 1.651-r0
|
Original advisory text
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.
DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.
SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.
The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.
DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.
SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.
The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.
References
- https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d...
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
- http://www.openwall.com/lists/oss-security/2026/07/14/9
- https://metacpan.org/release/HMBRAND/DBI-1.651/changes release-notes
- https://www.cve.org/CVERecord?id=CVE-2026-15043 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-15043 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/41805128/ Third Party Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-15043 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15043... Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-15043 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-15043 Vendor Advisory
- https://github.com/perl5-dbi/dbi Product
- https://cpan.org/modules URL
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-480Use of Incorrect Operator
Timeline
Published14 Jul 2026
Updated27 Sep 2026
First seen14 Jul 2026
Sources
CVE-2026-15043 · NVD
CVE-2026-15043 · MITRE
DEBIAN-CVE-2026-15043 · OSV
UBUNTU-CVE-2026-15043 · OSV
GHSA-mv45-ff6j-x9jp · GHSA
BELL-CVE-2026-15043 · OSV
CVE-2026-15043 · OSV
Track software like this
Free during beta