216.73.217.22

CVE-2026-49942

· Published 04/06/2026 17:16 · Modified 04/06/2026 19:16

Labels: CVE-2026-49942 2026-06-049b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2026-49942CWE-1289

Essential information

Published
04/06/2026 17:16
Modified
04/06/2026 19:16
Author
Creator
CVSS
7.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, which were ignored. This could allow network masks to accept larger networks. Leading zeros were also accepted, but treated as decimal instead of octal. This could lead to confusion about what networks are acceptable.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
net-cidr / set cpe:2.3:a:net-cidr:set:<0.20:*:*:*:*:*:*:*

References