The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask.
If the argument was not a well-formed IP address, then this would lead to indefinite recursion.
An attacker could use this to cause a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 0.21 of later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rrwo net\
|
|
| CPEs | cpe:2.3:a:rrwo:net\:\:cidr\:\:set:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Rrwo net\
|
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rrwo
Rrwo net::cidr::set |
|
| Vendors & Products |
Rrwo
Rrwo net::cidr::set |
Thu, 04 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 04 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask. If the argument was not a well-formed IP address, then this would lead to indefinite recursion. An attacker could use this to cause a denial of service. | |
| Title | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses | |
| Weaknesses | CWE-1287 CWE-674 |
|
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-04T18:45:40.658Z
Reserved: 2026-06-02T16:06:23.069Z
Link: CVE-2026-49941
Updated: 2026-06-04T18:45:40.658Z
Status : Analyzed
Published: 2026-06-04T17:16:33.173
Modified: 2026-06-08T16:37:29.237
Link: CVE-2026-49941
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:07:30Z