IP Address Handling Flaw in Net::CIDR::Set for Perl
CVE-2025-40911
6.5MEDIUM
What is CVE-2025-40911?
Net::CIDR::Set versions 0.10 through 0.13 for Perl have a vulnerability where leading zero characters in IP CIDR address strings are not properly handled. This flaw allows attackers to bypass access controls based on IP addresses, creating a potential security risk. Users may inadvertently input addresses in octal notation, leading to confusion between decimal and octal interpretations. This vulnerability leverages code from Net::CIDR::Lite, which has a related issue documented in previous security advisories.
Affected Version(s)
Net::CIDR::Set 0.10 <= 0.13
