|
|
Message-ID: <de5d8e03-86d3-48d7-a8c3-d26107f2c51f@cpansec.org> Date: Thu, 4 Jun 2026 17:09:26 +0100 From: Robert Rothenberg <rrwo@...nsec.org> To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com Subject: CVE-2026-49940: Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks ======================================================================== CVE-2026-49940 CPAN Security Group ======================================================================== CVE ID: CVE-2026-49940 Distribution: Net-CIDR-Set Versions: through 0.20 MetaCPAN: https://metacpan.org/dist/Net-CIDR-Set VCS Repo: https://github.com/robrwo/perl-Net-CIDR-Set Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks Description ----------- Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks. Problem types ------------- - CWE-1289 Improper Validation of Unsafe Equivalence in Input Solutions --------- Upgrade to version 0.21. References ---------- https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes https://nvd.nist.gov/vuln/detail/CVE-2025-40911 Timeline -------- - 2026-05-13: Issue reported to CPANSec - 2026-06-02: Net::CIDR::Set version 0.21 released with fix
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.