{"id":"AZL-86417","summary":"CVE-2026-45191 affecting package perl-Net-CIDR-Lite 0.22-2","details":"Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.\n\nMask forms like \"/00\" and \"/01\" pass validation and parse to the same prefix as their unpadded value.\n\nSee also CVE-2026-45190.","modified":"2026-08-30T05:24:52Z","published":"2026-05-10T21:16:29Z","upstream":["CVE-2026-45191"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45191"}],"affected":[{"package":{"name":"perl-Net-CIDR-Lite","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-Net-CIDR-Lite"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.22-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86417.json"}}],"schema_version":"1.9.0"}