Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Team
Team net::async::statsd::client |
|
| Vendors & Products |
Team
Team net::async::statsd::client |
Thu, 04 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Title | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-06-03T23:45:27.353Z
Updated: 2026-06-04T18:31:02.943Z
Reserved: 2026-05-16T01:26:22.806Z
Link: CVE-2026-8722
Updated: 2026-06-04T18:28:20.686Z
Status : Undergoing Analysis
Published: 2026-06-04T00:17:00.333
Modified: 2026-06-04T20:16:58.797
Link: CVE-2026-8722
No data.