
Perl CPAN CVE-2026-40198: Net::CIDR::Lite before 0.23 does not validate IPv6 group count, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/1 CVE-2026-40199: Net::CIDR::Lite before 0.23 mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/2
Post summary
The text announces two CVEs (CVE‑2026‑40198 and CVE‑2026‑40199) affecting Net::CIDR::Lite that allow IP ACL bypass due to incorrect IPv6 handling.



