Skip to main content

Threats Tagged 'cve-2026-40199'

View all threats tagged with 'cve-2026-40199'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-40199

Threats Tagged 'cve-2026-40199'

Click on any threat for detailed analysis and mitigation recommendations

0

Multiple vulnerabilities in perl-Net-CIDR-Lite can lead to IP ACL bypass due to improper validation of IP address formats and CIDR mask values. These include issues with trailing newlines or non-ASCII digits, extraneous leading zeros in CIDR masks, missing validation of IPv6 group counts, and mishandling of IPv4 mapped IPv6 addresses. The vulnerabilities affect SUSE Linux Enterprise Module for Development Tools 15 SP7 and related versions. No known exploits are reported in the wild. A security update addressing these issues has been released by the SUSE Product Security Team.

Join the discussion

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value instead of 17 bytes, misaligning the IPv4 part of the address. The wrong length causes incorrect results in mask operations (bitwise AND truncates to the shorter operand) and in find() / bin_find() which use Perl string comparison (lt/gt). This can cause find() to incorrectly match or miss addresses. Example: my $cidr = Net::CIDR::Lite->new("::ffff:192.168.1.0/120"); $cidr->find("::ffff:192.168.2.0"); # incorrectly returns true This is triggered by valid RFC 4291 IPv4 mapped addresses (::ffff:x.x.x.x). See also CVE-2026-40198, a related issue in the same function affecting malformed IPv6 addresses.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-40199
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses