CVE-2026-3257 PUBLISHED

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library

Assigner: CPANSec
Reserved: 26.02.2026 Published: 05.03.2026 Updated: 05.03.2026

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library.

UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

Product Status

Vendor TOKUHIROM
Product UnQLite
Versions Default: unaffected
  • affected from 0 to 0.06 (incl.)

Workarounds

Upgrade to UnQLite for Perl version 0.07 or later.

Solutions

UnQLite for Perl has been deprecated since version 0.06. Migrate to a different solution.

References

Problem Types

  • CWE-1395 Dependency on Vulnerable Third-Party Component CWE