CPANSA-Metrics-Any-Adapter-Statsd-2026-50639: Metrics-Any-Adapter-Statsd vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-10T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-10T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 6.5 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections.
Vulnerabilities
CVE-2026-50639
Vulnerability DescriptionMetrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet.
Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability.
In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections.
| Weakness | CWE-93 : Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Metrics-Any-Adapter-Statsd less than 0.04 |
|
Fixed
- Metrics-Any-Adapter-Statsd greater than or equal 0.04
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Metrics-Any-Adapter-Statsd-2026-50639 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-metrics-any-adapter-statsd-2026-50639.json - https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes external
https://metacpan.org/release/PEVANS/Metrics-Any-Adapter-Statsd-0.04/changes - https://www.cve.org/CVERecord?id=CVE-2026-50637 external
https://www.cve.org/CVERecord?id=CVE-2026-50637 - https://www.cve.org/CVERecord?id=CVE-2026-50638 external
https://www.cve.org/CVERecord?id=CVE-2026-50638 - https://www.cve.org/CVERecord?id=CVE-2026-9270 external
https://www.cve.org/CVERecord?id=CVE-2026-9270 - CVE-2026-50639 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-50639
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Wed Jun 10 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/