DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.
DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.
SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.
The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.
References
Configurations
No configuration.
History
14 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
14 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jul 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 10:16
Updated : 2026-07-14 16:44
NVD link : CVE-2026-15043
Mitre link : CVE-2026-15043
CVE.ORG link : CVE-2026-15043
JSON object : View
Products Affected
No product.
CWE
CWE-480
Use of Incorrect Operator
