Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <bc840dc9-fef9-4459-afca-3b5551ca30f2@cpansec.org>
Date: Thu, 4 Jun 2026 17:10:44 +0100
From: Robert Rothenberg <rrwo@...nsec.org>
To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com
Subject: CVE-2026-49941: Net::CIDR::Set versions through 0.20 for Perl did not
 validate IP addresses


========================================================================
CVE-2026-49941                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-49941
   Distribution:  Net-CIDR-Set
       Versions:  through 0.20

       MetaCPAN:  https://metacpan.org/dist/Net-CIDR-Set
       VCS Repo:  https://github.com/robrwo/perl-Net-CIDR-Set


Net::CIDR::Set versions through 0.20 for Perl did not validate IP
addresses

Description
-----------
Net::CIDR::Set versions through 0.20 for Perl did not validate IP
addresses.

The add method called the _encode method to parse addresses. If the
addresses did not look like netmasks or network ranges, then they were
assumed to single IP addresses and passed back to itself as a 32-bit or
128-bit netmask.

If the argument was not a well-formed IP address, then this would lead
to indefinite recursion.

An attacker could use this to cause a denial of service.

Problem types
-------------
- CWE-1287 Improper Validation of Specified Type of Input
- CWE-674 Uncontrolled Recursion

Solutions
---------
Upgrade to version 0.21 of later.


References
----------
https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes

Timeline
--------
- 2026-05-13: Issue reported to CPANSec
- 2026-06-02: Net::CIDR::Set version 0.21 released with fix



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.