CPANSA-Net-Statsd-2026-46739: Net-Statsd vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-04T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-04T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 5.3 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. The update_stats (used for updating counters) and gauge methods do not check that values are numeric (which would block metric injection).
Vulnerabilities
CVE-2026-46739
Vulnerability DescriptionNet::Statsd versions before 0.13 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
The update_stats (used for updating counters) and gauge methods do not check that values are numeric (which would block metric injection).
| Weakness | CWE-93 : Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Net-Statsd less than 0.13 |
|
Fixed
- Net-Statsd greater than or equal 0.13
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Net-Statsd-2026-46739 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-net-statsd-2026-46739.json - https://github.com/cosimo/perl5-net-statsd/pull/10 external
https://github.com/cosimo/perl5-net-statsd/pull/10 - https://www.cve.org/CVERecord?id=CVE-2026-46719 external
https://www.cve.org/CVERecord?id=CVE-2026-46719 - https://www.cve.org/CVERecord?id=CVE-2026-46720 external
https://www.cve.org/CVERecord?id=CVE-2026-46720 - CVE-2026-46739 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-46739
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Thu Jun 4 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/