Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses.
If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked.
Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.
Metrics
Affected Vendors & Products
References
History
Mon, 11 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rrwo
Rrwo plack::middleware::statsd |
|
| Vendors & Products |
Rrwo
Rrwo plack::middleware::statsd |
Sun, 10 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 10 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead. | |
| Title | Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses | |
| Weaknesses | CWE-319 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-05-10T19:10:57.492Z
Updated: 2026-05-10T21:17:03.221Z
Reserved: 2026-05-09T18:57:17.867Z
Link: CVE-2026-45179
No data.
Status : Received
Published: 2026-05-10T20:16:28.967
Modified: 2026-05-10T22:16:06.967
Link: CVE-2026-45179
No data.