CVE-2026-19566

Source
https://cve.org/CVERecord?id=CVE-2026-19566
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19566.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19566
Aliases
  • GHSA-grjr-r4x5-mx4p
Downstream
Published
2026-08-12T08:39:59.029Z
Modified
2026-08-15T04:25:18.858666667Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths
Details

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths.

The _encode method accepts any prefix length matching (0|[1-9][0-9]*) and passes it to _width2bits(), which builds the mask as '1' x ($width + 8), one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: ::/100000000 builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and guesscoder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it.

Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129 stringifies back unchanged, contains() of its own base address returns false, and removing it from a set drops the base address while the set still prints as covering it.

Database specific
{
    "cwe_ids": [
        "CWE-1284",
        "CWE-789"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19566.json",
    "cna_assigner": "CPANSec"
}
References

Affected packages

Git / github.com/robrwo/perl-net-cidr-set

Affected ranges

Type
GIT
Repo
https://github.com/robrwo/perl-net-cidr-set
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.23"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.16
0.17
0.18
0.19
0.20
0.21
v0.*
v0.13
v0.14
v0.15

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19566.json"