Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.

Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value.

See also CVE-2026-45190.

Project Subscriptions

Vendors Products
Stigtsp Subscribe
Net::cidr::lite Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 0.24 or newer, or apply the patch provided.


Workaround

No workaround given by the vendor.

History

Sun, 10 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Stigtsp
Stigtsp net::cidr::lite
Vendors & Products Stigtsp
Stigtsp net::cidr::lite

Sun, 10 May 2026 20:30:00 +0000

Type Values Removed Values Added
Description Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value. See also CVE-2026-45190.
Title Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
Weaknesses CWE-1289
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-05-10T20:15:53.897Z

Reserved: 2026-05-10T16:36:05.708Z

Link: CVE-2026-45191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-10T21:16:29.380

Modified: 2026-05-10T21:16:29.380

Link: CVE-2026-45191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T21:30:20Z

Weaknesses