PT-2026-90707 · Dbd::Dbm+2 · Dbd::Dbm+3

CVE-2026-78030

·

Published

2026-09-11

·

Updated

2026-09-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DBI versions prior to 1.653
Description An issue in DBD::DBM allows the loading of arbitrary modules because the dbm type and dbm mldbm connect attributes are passed to the require function without validation. Since require treats path-shaped strings as literal filenames and bypasses the @INC array, an attacker can specify a file path to load and execute arbitrary file-scope code. The MLDBM::Serializer:: prefix prepended to dbm mldbm does not act as a boundary, as values containing / can traverse out of the serializer directory. This can be exploited if an untrusted party can influence these attributes via a DSN fragment or a storage backend selection parameter. Additionally, DBD::Gofer forwards these attributes to the server side, and DBI::ProxyServer only verifies that a DSN starts with a driver prefix, potentially propagating the issue.
Recommendations Update DBI to version 1.653 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103475
CVE-2026-78030
ECHO-71D6-5F21-0FD8
GHSA-WQMW-WQWX-3FR7
OPENSUSE-SU-2026:11754-1
OPENSUSE-SU-2026:21960-1
SUSE-SU-2026:23919-1
SUSE-SU-2026:23952-1
SUSE-SU-2026:4346-1
SUSE-SU-2026:4386-1

Affected Products

Dbd::Dbm
Dbd::Gofer
Dbi
Dbi::Proxyserver