Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
No sign of exploitation. No public exploitation artifact known so far.
Net::CIDR::Lite Perl library before version 0.24 doesn't properly validate IP addresses and CIDR masks, allowing attackers to bypass IP access control lists (ACLs) by using malformed inputs like trailing newlines or invalid characters that get misinterpreted differently than intended.
The vulnerability stems from insufficient input validation in Net::CIDR::Lite where inputs with trailing newlines or non-ASCII characters pass validation but are re-encoded to different addresses during parsing, causing find() and bin_find() methods to incorrectly match or miss IP addresses. An attacker can craft malformed CIDR entries to bypass network-based IP ACLs that rely on this library.