Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.
Inputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.
Example:
my $cidr = Net::CIDR::Lite->new(); $cidr->add("::1\n/128"); $cidr->find("::1a"); # incorrectly returns true
See also CVE-2026-45191.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-net-cidr-lite | Jun 18, 2026 | May 10, 2026 |
| Debian | — | Upgrade libnet-cidr-lite-perl | Jul 12, 2026 | Jul 12, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 10, 2026 |
| Ubuntu | — | Upgrade libnet-cidr-lite-perlUpgrade libnet-cidr-lite-perl (Ubuntu Pro) | Jun 21, 2026 | Jun 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub