Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.
Newlines are not removed from metric names, allowing metric injections.
Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Apply the patch. Otherwise ensure that metric names and values come from trusted sources or are properly sanitised.
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 22 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections. | |
| Title | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections | |
| Weaknesses | CWE-150 CWE-93 |
|
| References |
|
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-22T15:33:17.415Z
Reserved: 2026-06-05T12:15:54.476Z
Link: CVE-2026-11373
Updated: 2026-06-22T15:32:37.202Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T17:30:04Z