CVE-2026-45180

HIGH

Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids

Title source: cna
STIX 2.1

Description

Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication tokens.

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
RRWO/Catalyst::Plugin::Statsd < 0.10.0
Published May 10, 2026
Tracked Since May 11, 2026