CVE-2026-60082: perl-DBI: perl-DBI: Denial of Service via out-of-bounds read

Severity: Critical

CVSS Score: 9.1

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.