CPANSA-Metrics-Any-Adapter-Statsd-2026-50637: Metrics-Any-Adapter-Statsd vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-10T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-10T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 8.2 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and statsd control characters (colon, pipe) then metric injections are possible. Version 0.04 fixed this by modifying the _make method to block metric names with characters below ASCII 32 (which includes the newline), or colons or pipes.
Vulnerabilities
CVE-2026-50637
Vulnerability DescriptionMetrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet.
The send method does not validate the contents of the metric names or values. If the names have newlines and statsd control characters (colon, pipe) then metric injections are possible.
Version 0.04 fixed this by modifying the _make method to block metric names with characters below ASCII 32 (which includes the newline), or colons or pipes.
| Weakness | CWE-93 : Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Metrics-Any-Adapter-Statsd less than 0.04 |
|
Fixed
- Metrics-Any-Adapter-Statsd greater than or equal 0.04
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Metrics-Any-Adapter-Statsd-2026-50637 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-metrics-any-adapter-statsd-2026-50637.json - https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes external
https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes - https://www.cve.org/CVERecord?id=CVE-2026-46719 external
https://www.cve.org/CVERecord?id=CVE-2026-46719 - https://www.cve.org/CVERecord?id=CVE-2026-46720 external
https://www.cve.org/CVERecord?id=CVE-2026-46720 - https://www.cve.org/CVERecord?id=CVE-2026-46739 external
https://www.cve.org/CVERecord?id=CVE-2026-46739 - https://www.cve.org/CVERecord?id=CVE-2026-50638 external
https://www.cve.org/CVERecord?id=CVE-2026-50638 - https://www.cve.org/CVERecord?id=CVE-2026-50639 external
https://www.cve.org/CVERecord?id=CVE-2026-50639 - CVE-2026-50637 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-50637
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Wed Jun 10 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/