ALPINE-CVE-2026-60081

Source
https://security.alpinelinux.org/vuln/CVE-2026-60081
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2026-60081.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALPINE-CVE-2026-60081
Upstream
Published
2026-07-14T16:17:03.647Z
Modified
2026-07-25T16:30:08.377779637Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

DBI::ProfileData versions before 1.651 for Perl do not limit the path index.

The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

References

Affected packages

Alpine:v3.24 / perl-dbi

Package

Name
perl-dbi
Purl
pkg:apk/alpine/perl-dbi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.651-r0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2026-60081.json"