Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86417.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86417
Upstream
Published
2026-05-10T21:16:29Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-45191 affecting package perl-Net-CIDR-Lite 0.22-2
Details

Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.

Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value.

See also CVE-2026-45190.

References

Affected packages

Azure Linux:3 / perl-Net-CIDR-Lite

Package

Name
perl-Net-CIDR-Lite
Purl
pkg:rpm/azure-linux/perl-Net-CIDR-Lite

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.22-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86417.json"