Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <de5d8e03-86d3-48d7-a8c3-d26107f2c51f@cpansec.org>
Date: Thu, 4 Jun 2026 17:09:26 +0100
From: Robert Rothenberg <rrwo@...nsec.org>
To: cve-announce@...urity.metacpan.org, oss-security@...ts.openwall.com
Subject: CVE-2026-49940: Net::CIDR::Set versions through 0.20 for Perl accept
 non-ASCII IP addresses and netmasks

========================================================================
CVE-2026-49940                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-49940
   Distribution:  Net-CIDR-Set
       Versions:  through 0.20

       MetaCPAN:  https://metacpan.org/dist/Net-CIDR-Set
       VCS Repo:  https://github.com/robrwo/perl-Net-CIDR-Set


Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP
addresses and netmasks

Description
-----------
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP
addresses and netmasks.

Unicode digits such as the Arabic-Indic One (U+0661) were accepted but
not properly parsed as numbers.  This could allow network masks to
accept larger networks.

Problem types
-------------
- CWE-1289 Improper Validation of Unsafe Equivalence in Input

Solutions
---------
Upgrade to version 0.21.


References
----------
https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes
https://nvd.nist.gov/vuln/detail/CVE-2025-40911

Timeline
--------
- 2026-05-13: Issue reported to CPANSec
- 2026-06-02: Net::CIDR::Set version 0.21 released with fix



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.