NIXPKGS-2026-1474
GitHub issue
published on
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored maintainer @stigtsp maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value. See also CVE-2026-45190.
References
Affected products
Net-CIDR-Lite
- <0.24
Matching in nixpkgs
pkgs.perlPackages.NetCIDRLite
Perl extension for merging IPv4 or IPv6 CIDR addresses
pkgs.perl5Packages.NetCIDRLite
Perl extension for merging IPv4 or IPv6 CIDR addresses
pkgs.perl538Packages.NetCIDRLite
Perl extension for merging IPv4 or IPv6 CIDR addresses
pkgs.perl540Packages.NetCIDRLite
Perl extension for merging IPv4 or IPv6 CIDR addresses
Package maintainers
Ignored maintainers (1)
-
@stigtsp Stig Palmquist <stig@stig.io>