DBI 1.650, 1.651, 1.652, 1.653 and 1.654 fix the following issues:
- CVE-2026-88815: Fix DBI::sql_type_cast on IV/NV
- CVE-2026-88816: Fix FetchHashKeyName on IV/NV
- CVE-2026-78030: Fix arbitrary module and file loading via dbm_type/dbm_mldbm
- CVE-2026-15392: Tighten symlink outside of f_dir
- CVE-2026-73194: Force placeholder limit on :# and :p# too
- CVE-2026-73193: Limit statements to 292 Mb in preparse
- CVE-2026-15043: Fix inverted comparisons for strings in DBI::SQL::Nano
- CVE-2026-15392: Fix DBD::File to ensure that the table is not a symlink outside of f_dir
- CVE-2026-60082: Fix an out-of-bounds error when a statement handle has no fields but the source row is not empty
- CVE-2026-60081: Add an overridable upper bound $MAX_PATH_DEPTH for DBI::ProfileData
- CVE-2026-14739: Set a hard limit of 99999 on '?' placeholders
- CVE-2026-14740: Fix out-of-bounds read in preparse of SQL that starts with a comment
- CVE-2026-14380: Fix code injection via Profile DSN attribute or DBI_PROFILE variable