Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1474

NIXPKGS-2026-1474
published on
updated 1 week, 4 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored maintainer @stigtsp maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass

Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value. See also CVE-2026-45190.

Affected products

Net-CIDR-Lite
  • <0.24

Matching in nixpkgs

Package maintainers

Ignored maintainers (1)