CPANSA-Net-Statsite-Client-2026-11373: Net-Statsite-Client vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-06-22T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-06-22T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.1 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
Vulnerabilities
CVE-2026-11373
Vulnerability DescriptionNet::Statsite::Client versions through 1.1.0 for Perl allow metric injections.
Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.
Newlines are not removed from metric names, allowing metric injections.
Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
| Weakness | CWE-93 : Improper Neutralization of CRLF Sequences ('CRLF Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Net-Statsite-Client greater than 0 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Net-Statsite-Client-2026-11373 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-net-statsite-client-2026-11373.json - http://armon.github.io/statsite external
http://armon.github.io/statsite - https://metacpan.org/release/JASEI/Net-Statsite-Client-1.1.0/view/lib/Net/Statsite/Client.pm external
https://metacpan.org/release/JASEI/Net-Statsite-Client-1.1.0/view/lib/Net/Statsite/Client.pm - https://security.metacpan.org/patches/N/Net-Statsite-Client/1.1.0/CVE-2026-11373-r1.patch external
https://security.metacpan.org/patches/N/Net-Statsite-Client/1.1.0/CVE-2026-11373-r1.patch - https://www.cve.org/CVERecord?id=CVE-2026-46719 external
https://www.cve.org/CVERecord?id=CVE-2026-46719 - https://www.cve.org/CVERecord?id=CVE-2026-46720 external
https://www.cve.org/CVERecord?id=CVE-2026-46720 - https://www.cve.org/CVERecord?id=CVE-2026-46739 external
https://www.cve.org/CVERecord?id=CVE-2026-46739 - CVE-2026-11373 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-11373
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Jun 22 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/