OVERVIEW CVE-2026-40199 is a logic error in Net::CIDR::Lite for Perl versions prior to 0.23 that affects IPv4 mapped IPv6 address handling. The _pack_ipv6() function incorrectly includes an extra sentinel byte when processing RFC 4291 compliant addresses in the format ::ffff:x.x.x.x, resulting in a malformed 18-byte representation instead of the correct 17 bytes. This misalignment causes ACL bypass vulnerabilities by enabling attackers to craft IP addresses that evade network access control lists relying on this library. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with a network-based attack vector requiring no privileges or user interaction. The defect occurs in both bitwise mask operations and the find() function's string comparison logic, allowing attackers to forge addresses that either incorrectly match or fail to match intended CIDR ranges. The impact includes both confidentiality and integrity compromise through IP-based security control circumvention, though availability is not directly affected. EXPLOITATION STATUS There is no evidence of active exploitation, as this CVE does not appear on the Known Exploited Vulnerabilities (KEV) catalog. The vulnerability remains on the Inactive Hot List with minimal community attention reflected in a low EPSS score of 0.00012. However, the straightforward nature of the logic error suggests exploit development would be trivial if this library is used in critical IP filtering applications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 0.23CPE match | cpe:2.3:a:stigtsp:net\:\:cidr\:\:lite:*:*:*:*:*:perl:*:* | ||
< 0.23CPE matchmatch criteria | cpe:2.3:a:stigtsp:net\:\:cidr\:\:lite:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.