Junglewise Threat Intelligence

CVE-2026-45190: STIGTSP Net::CIDR::Lite IP ACL bypass via improper input validation

CVE-2026-45190 · Severity: medium · CVSS 6.5 · Published 2026-05-10

Technologies: CPAN Net::CIDR::Lite. Vendors: CPAN.

Executive brief

A vulnerability in the Net::CIDR::Lite Perl library, which is used to manage and compare IP address ranges, could allow attackers to bypass security access controls. By providing specially crafted IP addresses containing hidden characters like newlines or non-standard digits, an attacker can trick the system into misidentifying their network location. This could result in unauthorized access to services or data that are supposed to be restricted to specific IP addresses.

Technical details

Net::CIDR::Lite versions before 0.24 contain an input validation flaw where the parser regexes use \d (which matches Unicode digits) and /^...$/ (which allows trailing newlines). These inputs pass initial validation but are subsequently re-encoded by the parser into different addresses than intended. Consequently, the find() and bin_find() methods may return incorrect results, leading to IP ACL bypasses. An attacker can exploit this by providing malformed IP strings that the library incorrectly matches against allowed ranges. The issue is fixed in version 0.24 by using stricter regex anchors (\A and \z) and limiting digit matching to [0-9].

Affected products

  • STIGTSP Net::CIDR::Lite before 0.24

Timeline

  • 2026-05-10: disclosed
  • 2026-05-10: patched: Fixed in version 0.24
  • 2026-05-10: advisory

References