Back

HIGH

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses

Published Jun 4, 2026

Description

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses.

The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask.

If the argument was not a well-formed IP address, then this would lead to indefinite recursion.

An attacker could use this to cause a denial of service.

Affected products

Remediation

Vendor solution

Upgrade to version 0.21 of later.

Metrics

Weaknesses (2)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Jun 4, 2026
Updated Jun 4, 2026
Reserved Jun 2, 2026
CISA Vulnrichment
Updated Jun 4, 2026
NVD
Status Analyzed
Modified Jul 22, 2026
Red Hat
Severity n/a
Public date n/a