CVE-2026-49940: Rrwo Net::cidr::set
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers. This could allow network masks to accept larger networks.
Affected products
- Rrwo Net::cidr::set: before 0.21 (fixed in 0.21)
Published 2026-06-04. Last modified 2026-07-22.