๐Ÿ” CVE Alert

CVE-2026-78183

UNKNOWN 0.0

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL, which is length + 3 bytes. Every recognised literal (case-insensitive) overflows by 2 bytes, a single quote and a NULL. This can be reached by the $dbh->quote method, for example $dbh->quote( "Infinity", DBI::SQL_NUMERIC ). This regression was introduced in 3.21.0 by the quote.c rewrite.

CWE CWE-787
Published Aug 23, 2026
Last Updated Aug 23, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bucardo/dbdpg/security/advisories/GHSA-785p-fw3v-r822 metacpan.org: https://metacpan.org/release/TURNSTEP/DBD-Pg-3.21.1/source/Changes github.com: https://github.com/bucardo/dbdpg/commit/6d6f47ed2403cda55c82b1bad56e388ba7390065.patch github.com: https://github.com/bucardo/dbdpg/commit/adacf1de872326a465e13f9e4281a674ebcd227e openwall.com: http://www.openwall.com/lists/oss-security/2026/08/23/5