CVE-2026-40198Disclosure(stigtsp / net\)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactly 8 hex groups. Inputs like "abcd", "1:2:3", or "1:2:3:4:5:6:7" are accepted and produce packed values of wrong length (3, 7, or 15 bytes instead of 17). The packed values are used internally for mask and comparison operations. find() and bin_find() use Perl string comparison (lt/gt) on these values, and comparing strings of different lengths gives wrong results. This can cause find() to incorrectly report an address as inside or outside a range. Example: my $cidr = Net::CIDR::Lite->new("::/8"); $cidr->find("1:2:3"); # invalid input, incorrectly returns true This is the same class of input validation issue as CVE-2021-47154 (IPv4 leading zeros) previously fixed in this module. See also CVE-2026-40199, a related issue in the same function affecting IPv4 mapped IPv6 addresses.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • net\

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
net\

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-11: 4Technical Details · 2026-04-11: 404-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-40198: Net::CIDR::Lite before 0.23 does not validate IPv6 group count, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/1 CVE-2026-40199: Net::CIDR::Lite before 0.23 mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/2

    Post summary

    The text announces two CVEs (CVE‑2026‑40198 and CVE‑2026‑40199) affecting Net::CIDR::Lite that allow IP ACL bypass due to incorrect IPv6 handling.

    00030374
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40198 Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 a… https://www.cve.org/CVERecord?id=CVE-2026-40198

    Post summary

    CVE‑2026‑40198 is a vulnerability in Net::CIDR::Lite versions prior to 0.23 that fails to validate IPv6 group counts, potentially allowing ACL bypass; the post provides technical details but no exploit, patch, or PoC information.

    00000138
    57.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass Intel Report: https://ift.tt/2bf7QmM

    Post summary

    The alert provides initial technical details on CVE-2026-40198 and its potential to bypass IP ACLs via malformed IPv6 group counts, but offers no evidence of exploitation, a PoC, or mitigation guidance.

    0000029
    280 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40198 IPv6 Group Count Validation Bypass in Net::CIDR::Lite Before 0.23 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40198

    Post summary

    The post references CVE‑2026‑40198, describing it as an IPv6 group count validation bypass in Net::CIDR::Lite before 0.23, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstigtspnet\\--

Explore more