Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <D80998EF-B823-448B-B82E-C14B82E25578@stig.io>
Date: Sun, 10 May 2026 22:23:39 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
 oss-security@...ts.openwall.com
Subject: CVE-2026-45190: Net::CIDR::Lite versions before 0.24 for Perl does
 not properly validate IP address and CIDR mask inputs, which may allow IP ACL
 bypass

========================================================================
CVE-2026-45190                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2026-45190
  Distribution:  Net-CIDR-Lite
      Versions:  before 0.24

      MetaCPAN:  https://metacpan.org/dist/Net-CIDR-Lite
      VCS Repo:  https://github.com/stigtsp/Net-CIDR-Lite


Net::CIDR::Lite versions before 0.24 for Perl does not properly
validate IP address and CIDR mask inputs, which may allow IP ACL bypass

Description
-----------
Net::CIDR::Lite versions before 0.24 for Perl does not properly
validate IP address and CIDR mask inputs, which may allow IP ACL
bypass.

Inputs containing a trailing newline or non-ASCII digit characters pass
the validators but are then re-encoded by the parser to a different
address than the input string spelled. find() and bin_find() can match
or miss addresses as a result.

Example:

  my $cidr = Net::CIDR::Lite->new();
  $cidr->add("::1\n/128");
  $cidr->find("::1a");  # incorrectly returns true

See also CVE-2026-45191.

Problem types
-------------
- CWE-1289 Improper Validation of Unsafe Equivalence in Input

Solutions
---------
Upgrade to version 0.24 or newer, or apply the patch provided.


References
----------
https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch
https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes
https://www.cve.org/CVERecord?id=CVE-2026-45191

Timeline
--------
- 2026-05-10: Vulnerability found
- 2026-05-10: Net-CIDR-Lite version 0.24 released

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.