CVE-2026-40199 Details
Description
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value instead of 17 bytes, misaligning the IPv4 part of the address. The wrong length causes incorrect results in mask operations (bitwise AND truncates to the shorter operand) and in find() / bin_find() which use Perl string comparison (lt/gt). This can cause find() to incorrectly match or miss addresses. Example: my $cidr = Net::CIDR::Lite->new("::ffff:192.168.1.0/120"); $cidr->find("::ffff:192.168.2.0"); # incorrectly returns true This is triggered by valid RFC 4291 IPv4 mapped addresses (::ffff:x.x.x.x). See also CVE-2026-40198, a related issue in the same function affecting malformed IPv6 addresses.
A vulnerability exists in Net::CIDR::Lite for Perl, specifically in versions prior to 0.23, due to improper handling of IPv4 mapped IPv6 addresses. The issue arises because the _pack_ipv6() function incorrectly includes a sentinel byte from _pack_ipv4() when creating the packed representation of these addresses. This error results in an 18-byte value instead of the correct 17 bytes, misaligning the IPv4 portion of the address. The incorrect length leads to errors in mask operations, where a bitwise AND truncates to the shorter operand, and in the find() and bin_find() methods, which rely on Perl's string comparison. As a result, find() may incorrectly match or overlook addresses. This vulnerability is triggered by valid IPv6 addresses that are mapped from IPv4, following the RFC 4291 specification.
Users can upgrade to Net::CIDR::Lite version 0.23 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/stigtsp/Net-CIDR-Lite/commit/b7166b1fa17b3b14b4c795ace5b3fbf71a0bd04a.patch | CPANSec | Patch |
| https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.23/changes | CPANSec | Release Notes |
| https://www.cve.org/CVERecord?id=CVE-2026-40198 | CPANSec | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| stigtsp net::cidr::lite | < 0.23 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CPANSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 13, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | New CVE Received | CPANSec |