Denial of Service Vulnerability in Net::CIDR::Set for Perl
CVE-2026-49941

7.5HIGH

Key Information:

Vendor

Rrwo

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49941?

The Net::CIDR::Set module for Perl is susceptible to a denial of service due to insufficient validation of IP addresses. The add method incorrectly handles non-well-formed addresses by entering an indefinite recursive loop, which can be exploited by attackers. This vulnerability allows malicious users to initiate requests that ultimately crash the application, resulting in service unavailability.

Affected Version(s)

Net::CIDR::Set 0 <= 0.20

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.