CPANSA-Metrics-Any-Adapter-Statsd-2026-50638: Metrics-Any-Adapter-Statsd vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-10T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-10T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.1 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injections.
Vulnerabilities
CVE-2026-50638
Vulnerability DescriptionMetrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet.
Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability.
In addition, the _tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injections.
| Weakness | CWE-93 : Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Metrics-Any-Adapter-Statsd less than 0.04 |
|
Fixed
- Metrics-Any-Adapter-Statsd greater than or equal 0.04
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Metrics-Any-Adapter-Statsd-2026-50638 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-metrics-any-adapter-statsd-2026-50638.json - https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes external
https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes - https://www.cve.org/CVERecord?id=CVE-2026-50637 external
https://www.cve.org/CVERecord?id=CVE-2026-50637 - https://www.cve.org/CVERecord?id=CVE-2026-50639 external
https://www.cve.org/CVERecord?id=CVE-2026-50639 - https://www.cve.org/CVERecord?id=CVE-2026-9270 external
https://www.cve.org/CVERecord?id=CVE-2026-9270 - CVE-2026-50638 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-50638
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Wed Jun 10 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/