CVE-2026-49941
Received Received - Intake
Recursive DoS in Net::CIDR::Set Perl Module

Publication date: 2026-06-04

Last updated on: 2026-06-04

Assigner: CPANSec

Description
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask. If the argument was not a well-formed IP address, then this would lead to indefinite recursion. An attacker could use this to cause a denial of service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-04
Last Modified
2026-06-04
Generated
2026-06-04
AI Q&A
2026-06-04
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1287 The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Net::CIDR::Set versions through 0.20 for Perl, where the software does not properly validate IP addresses.

The add method calls the _encode method to parse addresses. If the addresses do not resemble netmasks or network ranges, they are assumed to be single IP addresses and are passed back to the method as a 32-bit or 128-bit netmask.

If the argument is not a well-formed IP address, this causes indefinite recursion, which can be exploited by an attacker.


How can this vulnerability impact me? :

An attacker could exploit this vulnerability to cause a denial of service (DoS) by triggering indefinite recursion in the IP address parsing function.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart