CVE-2026-49941
Description
Net::CIDR::Set versions through 0.20 for Perl are vulnerable to indefinite recursion and denial of service due to improper IP address validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Net::CIDR::Set versions through 0.20 for Perl are vulnerable to indefinite recursion and denial of service due to improper IP address validation.
Vulnerability
The Net::CIDR::Set Perl module, in versions through 0.20, fails to properly validate IP addresses passed to its add method. When addresses are not recognized as netmasks or network ranges, they are assumed to be single IP addresses and are passed back to the _encode method. If the argument is not a well-formed IP address, this leads to indefinite recursion.
Exploitation
An attacker can trigger this vulnerability by providing a malformed IP address to the add method of the Net::CIDR::Set module. This requires the attacker to be able to influence the input to the module, such as through a web application or other service that utilizes this library for IP address processing.
Impact
Successful exploitation of this vulnerability can lead to a denial of service (DoS) condition. The indefinite recursion consumes system resources, potentially causing the application or server running the vulnerable code to become unresponsive.
Mitigation
This vulnerability was fixed in Net::CIDR::Set version 0.21, released on 2026-06-02. Users are advised to upgrade to version 0.21 or later to address the issue [1].
AI Insight generated on Jun 4, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=0.20
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.