Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks.
Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks.
References
| Link | Resource |
|---|---|
| https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes | Release Notes |
| https://nvd.nist.gov/vuln/detail/CVE-2025-40911 | Third Party Advisory US Government Resource |
Configurations
History
08 Jun 2026, 16:35
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes - Release Notes | |
| References | () https://nvd.nist.gov/vuln/detail/CVE-2025-40911 - Third Party Advisory, US Government Resource | |
| First Time |
Rrwo net\
Rrwo |
|
| CPE | cpe:2.3:a:rrwo:net\:\:cidr\:\:set:*:*:*:*:*:perl:*:* |
04 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
04 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 17:16
Updated : 2026-06-08 16:35
NVD link : CVE-2026-49940
Mitre link : CVE-2026-49940
CVE.ORG link : CVE-2026-49940
JSON object : View
Products Affected
rrwo
- net\
CWE
CWE-1289
Improper Validation of Unsafe Equivalence in Input
