
Perl CPAN: CVE-2026-45190: Net::CIDR::Lite before 0.24 does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass https://www.openwall.com/lists/oss-security/2026/05/10/6 CVE-2026-45191: ditto with extraneous zero characters in CIDR mask values https://www.openwall.com/lists/oss-security/2026/05/10/7
Post summary
Two CVEs (2026‑45190 & 2026‑45191) affecting Net::CIDR::Lite have been disclosed, noting that improper input validation can allow IP ACL bypass and issues with extraneous zeros in CIDR masks.

