CVE-2026-50638

CRITICAL

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections

Title source: cna
STIX 2.1

Description

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injections.

Scores

CVSS v3 9.1
EPSS 0.0032
EPSS Percentile 23.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-93
Status published
Products (1)
PEVANS/Metrics::Any::Adapter::DogStatsd < 0.04
Published Jun 10, 2026
Tracked Since Jun 11, 2026