Threats Tagged 'cve-2026-40199'
View all threats tagged with 'cve-2026-40199'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-40199'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple vulnerabilities in perl-Net-CIDR-Lite can lead to IP ACL bypass due to improper validation of IP address formats and CIDR mask values. These include issues with trailing newlines or non-ASCII digits, extraneous leading zeros in CIDR masks, missing validation of IPv6 group counts, and mishandling of IPv4 mapped IPv6 addresses. The vulnerabilities affect SUSE Linux Enterprise Module for Development Tools 15 SP7 and related versions. No known exploits are reported in the wild. A security update addressing these issues has been released by the SUSE Product Security Team. Join the discussion | GCVE Database | 05/29/2026, 15:24:46 UTC Added: 05/31/2026, 21:00:26 UTC |
0 Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value instead of 17 bytes, misaligning the IPv4 part of the address. The wrong length causes incorrect results in mask operations (bitwise AND truncates to the shorter operand) and in find() / bin_find() which use Perl string comparison (lt/gt). This can cause find() to incorrectly match or miss addresses. Example: my $cidr = Net::CIDR::Lite->new("::ffff:192.168.1.0/120"); $cidr->find("::ffff:192.168.2.0"); # incorrectly returns true This is triggered by valid RFC 4291 IPv4 mapped addresses (::ffff:x.x.x.x). See also CVE-2026-40198, a related issue in the same function affecting malformed IPv6 addresses. Join the discussion | CVE Database V5 | 04/10/2026, 21:49:48 UTC Added: 04/10/2026, 22:05:47 UTC |
Showing 1 to 2 of 2 results