Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections.
The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Version 0.06 changes the module from being a statsd client to using a separate statsd client. It defaults to using a version of Net::Statsd::Tiny that fixes a similar issue (CVE-2026-46720).
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rrwo
Rrwo mojolicious::plugin::statsd |
|
| Vendors & Products |
Rrwo
Rrwo mojolicious::plugin::statsd |
Tue, 26 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a separate statsd client. It defaults to using a version of Net::Statsd::Tiny that fixes a similar issue (CVE-2026-46720). | |
| Title | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published: 2026-05-26T22:48:03.747Z
Updated: 2026-05-26T22:48:03.747Z
Reserved: 2026-05-17T18:04:31.500Z
Link: CVE-2026-46740
No data.
Status : Deferred
Published: 2026-05-26T23:16:20.923
Modified: 2026-05-27T19:38:33.270
Link: CVE-2026-46740
No data.