PT-2026-46268 · Cpan · Net::Cidr::Set

CVE-2026-49942

·

Published

2026-06-04

·

Updated

2026-06-07

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Net::CIDR::Set versions prior to 0.21
Description Net::CIDR::Set for Perl fails to properly validate network masks. The mask portion may contain non-digits or Unicode digits, such as the Arabic-Indic One (U+0661), which are ignored, potentially allowing the acceptance of larger networks. Additionally, leading zeros are treated as decimal values rather than octal, which can cause ambiguity regarding acceptable networks.
Recommendations Update to a version later than 0.20.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49942

Affected Products

Net::Cidr::Set