Non-ASCII IP Address Parsing Vulnerability in Net::CIDR::Set by Perl
CVE-2026-49940
6.5MEDIUM
What is CVE-2026-49940?
The Net::CIDR::Set module for Perl permits non-ASCII characters in IP addresses and network masks, specifically handling Unicode digits like the Arabic-Indic One (U+0661) without proper validation and parsing. This flaw could potentially allow the input of larger networks than intended, posing significant risks to network configurations and security protocols.
Affected Version(s)
Net::CIDR::Set 0 <= 0.20
