Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
HMBRAND DBI — DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0046 38.5 —
AFFECTED
Product Versions Fixed
DBI unspecified —
TIMELINE
May 27 Reserved by CPANSec
Jun 9 Published (CNA: CPANSec)
Aug 11 RESCORED — CVE-2026-9698 (HMBRAND DBI). CVSS 7.5 → 9.8 (NVD).
Description
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer.
Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit.
Attackers that can influence the error text in an application can trigger a buffer overflow.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 27, 2026 | Reserved | Reserved by CPANSec |
| June 9, 2026 | Published | Published (CNA: CPANSec) |
| August 11, 2026 | RESCORED | RESCORED — CVE-2026-9698 (HMBRAND DBI). CVSS 7.5 → 9.8 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| HMBRAND | DBI | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-9698 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.