Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.
Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value.
See also CVE-2026-45190.
Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value.
See also CVE-2026-45190.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 0.24 or newer, or apply the patch provided.
Workaround
No workaround given by the vendor.
References
History
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stigtsp
Stigtsp net::cidr::lite |
|
| Vendors & Products |
Stigtsp
Stigtsp net::cidr::lite |
Sun, 10 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value. See also CVE-2026-45190. | |
| Title | Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass | |
| Weaknesses | CWE-1289 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-10T20:15:53.897Z
Reserved: 2026-05-10T16:36:05.708Z
Link: CVE-2026-45191
No data.
Status : Received
Published: 2026-05-10T21:16:29.380
Modified: 2026-05-10T21:16:29.380
Link: CVE-2026-45191
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:30:20Z
Weaknesses