Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.
Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.
Newlines are not removed from metric names, allowing metric injections.
Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jasei
Jasei net::statsite::client |
|
| Vendors & Products |
Jasei
Jasei net::statsite::client |
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 22 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections. | |
| Title | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections | |
| Weaknesses | CWE-150 CWE-93 |
|
| References |
|
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-06-22T11:28:06.211Z
Updated: 2026-06-22T15:33:17.415Z
Reserved: 2026-06-05T12:15:54.476Z
Link: CVE-2026-11373
Updated: 2026-06-22T15:32:37.202Z
No data.
No data.
ReportizFlow