CVE-2026-40199Disclosure(stigtsp / net\)

LOWCVSS 6.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value instead of 17 bytes, misaligning the IPv4 part of the address. The wrong length causes incorrect results in mask operations (bitwise AND truncates to the shorter operand) and in find() / bin_find() which use Perl string comparison (lt/gt). This can cause find() to incorrectly match or miss addresses. Example: my $cidr = Net::CIDR::Lite->new("::ffff:192.168.1.0/120"); $cidr->find("::ffff:192.168.2.0"); # incorrectly returns true This is triggered by valid RFC 4291 IPv4 mapped addresses (::ffff:x.x.x.x). See also CVE-2026-40198, a related issue in the same function affecting malformed IPv6 addresses.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • net\

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
net\

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-11: 4Technical Details · 2026-04-11: 404-11
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-40198: Net::CIDR::Lite before 0.23 does not validate IPv6 group count, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/1 CVE-2026-40199: Net::CIDR::Lite before 0.23 mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/04/11/2

    Post summary

    The post discloses two Net::CIDR::Lite CVEs that enable IP ACL bypass due to insufficient validation; no PoC, exploit, or patch information is present.

    00030374
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40199 Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pac… https://www.cve.org/CVERecord?id=CVE-2026-40199

    Post summary

    The post announces that Net::CIDR::Lite versions before 0.23 have a flaw where IPv4‑mapped IPv6 addresses are mishandled, potentially enabling bypass of IP access control lists.

    00010184
    57.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass Intel Report: https://ift.tt/nTXpwL0

    Post summary

    The post announces CVE-2026-40199 affecting Net::CIDR::Lite, noting a flaw that could allow IP ACL bypass via IPv4‑mapped IPv6 addresses; no exploit, patch, or active use is reported.

    0000030
    280 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40199 IP ACL Bypass via IPv4 Mapped IPv6 Address Mishandling in Net::CIDR::Lit... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40199 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The message notes CVE-2026-40199 and provides a concise technical description of an IP ACL bypass involving IPv4 mapped IPv6 addresses, but offers no further details such as PoC, exploit code, or remediation.

    0000077
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstigtspnet\\--

Explore more