GHSA-fff7-gx98-vr3g · Severity: high — Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion...
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, which were ignored. This could allow network masks to accept larger networks. Leading zeros were also accepted, but treated as decimal instead of octal. This could lead to confusion about what networks are acceptable.
Conclusion & alert: CVE-2026-49942 is rated Moderate Risk (42.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.49%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.49% | +0.45% |
| 2 | 2026-06-09 | 0.05% | 0.04% | -0.01% |
| 3 | 2026-06-05 | — | 0.05% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
3.9 | 3.4 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-fff7-gx98-vr3g · Severity: high — Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-49942 not yet assigned priority: Debian including 1 source packages (libnet-cidr-set-perl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-49942 |
ubuntu
|
medium | CVE-2026-49942 medium priority: Ubuntu including 1 source packages (libnet-cidr-set-perl), 6 status rows across 6 suites (focal, jammy, noble, questing, resolute, upstream): needs-triage 5, released 1. | https://ubuntu.com/security/CVE-2026-49942 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| rrwo | net::cidr::set | < 0.21 | cpe:2.3:a:rrwo:net\:\:cidr\:\:set:*:*:*:*:*:perl:*:* |
| URL | Tags |
|---|---|
| https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes | Release Notes |
| https://nvd.nist.gov/vuln/detail/CVE-2025-40911 | Third Party Advisory US Government Resource |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45191 | Third Party Advisory US Government Resource |