Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Ensure only trusted data is submitted to metrics.
References
History
Thu, 04 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Title | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-03T23:45:27.353Z
Reserved: 2026-05-16T01:26:22.806Z
Link: CVE-2026-8722
No data.
Status : Received
Published: 2026-06-04T00:17:00.333
Modified: 2026-06-04T00:17:00.333
Link: CVE-2026-8722
No data.
OpenCVE Enrichment
No data.
Weaknesses