CVE•Published 2026-07-14•Modified 2026-07-14•1 article on news•6 live references•NVD data

CVE-2026-15043

Vulnerability data via NVD (ingested)

CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Description

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.

Timeline
Published 2026-07-14
Modified 2026-07-14

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

Josh-blythe/bordair-multimodalPython
Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities. Research-backed by OWASP LLM Top 10…
★ 75·updated 2mo ago
EvanThomasLuke/Awesome-AI-Security-Benchmarksunknown
List of AI Security benchmarks
★ 35·updated 1mo ago
Laprovittera/Awesome-AI-for-Hacking-Cybersecurityunknown
Lista curada y fusionada de agentes, herramientas, frameworks, modelos y papers de IA aplicada al hacking, pentesting y ciberseguridad (ofensiva y defensiva), y a la seguridad de l…
★ 12·updated 2w ago
VyetGokyra/awaresome_LLM_eval_benchmarkunknown
250 LLM Benchmarks & Evaluation Datasets
★ 10·updated 1w ago
martinholovsky/awesome-llm-attacksunknown
A curated, framework-mapped catalog of attack techniques against LLM and GenAI systems — cross-referenced to OWASP LLM Top 10, MITRE ATLAS, OWASP ASI, and MCP security.
★ 9·updated 1mo ago
8kSec/awesome-ai-securityunknown
A practitioner-focused reference for AI/ML security — attacks, tools, research, and defenses. Covers offensive AI, securing AI systems, AI-assisted security operations, and governa…
★ 4·updated 5mo ago
fevziegeyurtsevenler/AI-Security-Ogrenme-Rehberiunknown
AI Security Öğrenme Rehberi: Yapay zeka güvenliği alanında kariyer yapmak isteyenler için pratik rehber. Python temellerinden bug bounty süreçlerine, Türkiye pazarındaki fırsatlar …
★ 3·updated 5d ago
amurlaniakea/misdirection-proxyPython
Defensive Misdirection Proxy for AI Agents — CMPE implementation against automated jailbreak attacks
★ 3·updated 3mo ago