The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Ensure only trusted data is submitted to metrics.
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Team
Team net::async::statsd::client |
|
| Vendors & Products |
Team
Team net::async::statsd::client |
Thu, 04 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Title | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-04T18:31:02.943Z
Reserved: 2026-05-16T01:26:22.806Z
Link: CVE-2026-8722
Updated: 2026-06-04T18:28:20.686Z
Status : Undergoing Analysis
Published: 2026-06-04T00:17:00.333
Modified: 2026-06-04T20:16:58.797
Link: CVE-2026-8722
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:11:13Z