Home

Description

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

PUBLISHED Reserved 2026-02-26 | Published 2026-03-05 | Updated 2026-03-05 | Assigner CPANSec

Problem types

CWE-1395 Dependency on Vulnerable Third-Party Component

Product status

Default status
unaffected

Any version
affected

References

metacpan.org/release/TOKUHIROM/UnQLite-0.07/source/Changes release-notes

www.cve.org/CVERecord?id=CVE-2025-3791 vendor-advisory related vdb-entry

unqlite.symisc.net/

cve.org (CVE-2026-3257)

nvd.nist.gov (CVE-2026-3257)

Download JSON