CVE 5.3 MEDIUM

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections_CVE-2026-46740

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections.

The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Version 0.06 changes the module from being a statsd client to using a separate statsd client. It defaults to using a version of Net::Statsd::Tiny that fixes a similar issue (CVE-2026-46720).

Basic Information

ID CVE-2026-46740
Source CPANSec
Published May 26, 2026 at 22:48
Modified May 28, 2026 at 14:20

Affected Product

Vendor RRWO
Product Mojolicious::Plugin::Statsd
Affected Versions RRWO Mojolicious::Plugin::Statsd 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.