CVE 9.8 CRITICAL

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags_CVE-2026-11362

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.

DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.

The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)

AI Analysis

Metric injections from event tags are allowed due to lack of input sanitization in DataDog::DogStatsd versions through 0.07 for Perl

Basic Information

ID CVE-2026-11362
Source CPANSec
Published Jun 5, 2026 at 14:50
Modified Jun 8, 2026 at 18:20

Affected Product

Vendor BINARY
Product DataDog::DogStatsd
Affected Versions BINARY DataDog::DogStatsd 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor DataDog
Product DataDog::DogStatsd
Version 0.07

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.