{"id":"ALPINE-CVE-2026-60082","details":"DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.\n\nWhen the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.\n\nThis could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.","modified":"2026-08-27T22:17:57.473673782Z","published":"2026-07-14T16:17:03.750Z","upstream":["CVE-2026-60082"],"references":[{"type":"ADVISORY","url":"https://security.alpinelinux.org/vuln/CVE-2026-60082"}],"affected":[{"package":{"name":"perl-dbi","ecosystem":"Alpine:v3.24","purl":"pkg:apk/alpine/perl-dbi?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.651-r0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2026-60082.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}