Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
History

Tue, 23 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Jasei
Jasei net::statsite::client
Vendors & Products Jasei
Jasei net::statsite::client

Mon, 22 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 12:00:00 +0000

Type Values Removed Values Added
Description Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
Title Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
Weaknesses CWE-150
CWE-93
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published: 2026-06-22T11:28:06.211Z

Updated: 2026-06-22T15:33:17.415Z

Reserved: 2026-06-05T12:15:54.476Z

Link: CVE-2026-11373

cve-icon Vulnrichment

Updated: 2026-06-22T15:32:37.202Z

cve-icon NVD

No data.

cve-icon Redhat

No data.