ZeroHour
Product

Net::IP::LPM

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths

CVE-2026-86287: Net::IP::LPM Perl library before 1.12 accepts malformed IP prefix lengths, risking incorrect longest-prefix-match results.

Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths, per an oss-security disclosure posted September 7, 2026. The lax input validation in this longest-prefix-match library could produce incorrect matching behavior. The fix is available in version 1.12 on CPAN.

oss-security · 8d agoVulnerabilityCVE-2026-86287

Related CVEs

  • Improper Input Validation in Net::IP::LPM Perl Module Lets Bad Masks Poison Lookups
    Net::IP::LPM, a Perl module for longest-prefix-match IP lookups in versions before 1.12, improperly validates prefix lengths (CWE-1287): non-numeric and non-ASCII values are accepted and treated as 0, and prefix-length integers over 31 bits are silently truncated. A single malformed prefix length fed to the module — from untrusted input, configuration, or another data source — poisons the shared lookup table so that every subsequent lookup silently succeeds. The practical result is that allow-lists permit every address (a control bypass) and deny-lists block every address (a denial of service), consistent with the CVSS 7.5 (High) score that rates only availability impact. Any Perl application or service using Net::IP::LPM for access-control or routing-style decisions is affected, especially where prefix lengths are not strictly validated before insertion. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS places the 30-day exploitation probability at 0.4%, so no exploitation is currently known.
    · CPAN (Perl) Net::IP::LPM All versions before 1.12niche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.