Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
CVE-2026-49940
Currently unrated
What is CVE-2026-49940?
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks.
Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks.
Affected Version(s)
Net::CIDR::Set 0 <= 0.20
