Junglewise Threat Intelligence

CVE-2026-40198: Net::CIDR::Lite IP ACL bypass via improper IPv6 validation

CVE-2026-40198 · Severity: high · CVSS 7.5 · Published 2026-04-10

Technologies: Stig Palmquist (STIGTSP) Net::CIDR::Lite.

Executive brief

A vulnerability in a popular Perl library used for managing IP address ranges could allow attackers to bypass security access controls. By providing malformed IPv6 addresses, an attacker can trick the software into incorrectly identifying an address as being part of a trusted network. This could lead to unauthorized access to restricted services or data that rely on IP-based filtering.

Technical details

The vulnerability exists in the _pack_ipv6() function of Net::CIDR::Lite before version 0.23. The function fails to verify that uncompressed IPv6 addresses (those without the '::' shorthand) contain exactly eight hex groups. When malformed inputs with fewer groups are provided, the library generates packed binary values of incorrect lengths. Because internal functions like find() and bin_find() use standard Perl string comparisons (lt/gt) on these packed values, comparing strings of mismatched lengths results in incorrect logic, potentially returning 'true' for addresses that should be outside a specified CIDR range. This is fixed in version 0.23 by ensuring the group count is strictly validated.

Affected products

  • Stig Palmquist (STIGTSP) Net::CIDR::Lite versions before 0.23

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: patched: Fixed in version 0.23
  • 2026-04-10: advisory

References

Related threats