CVE-2026-15043

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.
Configurations

No configuration.

History

14 Jul 2026, 16:16

Type Values Removed Values Added
References
  • () https://metacpan.org/release/HMBRAND/DBI-1.651/changes -

14 Jul 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

14 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/07/14/9 -

14 Jul 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 10:16

Updated : 2026-07-14 16:44


NVD link : CVE-2026-15043

Mitre link : CVE-2026-15043

CVE.ORG link : CVE-2026-15043


JSON object : View

Products Affected

No product.

CWE
CWE-480

Use of Incorrect Operator