8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections.
The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Basic Information
ID
CVE-2026-46720
Source
CPANSec
Published
May 17, 2026 at 17:51
Modified
May 18, 2026 at 12:54
Affected Product
Vendor
RRWO
Product
Net::Statsd::Tiny
Affected Versions
RRWO Net::Statsd::Tiny 0