Description
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections.
The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Basic information
- Type
- unreviewed
- Severity
- medium
- Advisory on GitHub
- Open advisory ↗
- Repository advisory
- —
- Source code
- Not specified
- Published (advisory)
- 2026-05-16 15:31:13 UTC
- Updated
- 2026-05-19 15:31:22 UTC
- NVD published
- 2026-05-16
EPSS Score
| Score |
Percentile |
|
0.01%
|
1.87% |
CVSS Scores
| Base score |
Version |
Severity |
Vector |
|
6.5
|
3.1 |
—
|
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Click to expand
- Attack vector (AV:N)
- Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
- Attack complexity (AC:L)
- Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
- Privileges required (PR:N)
- No account or special rights needed—anonymous or random user is enough.
- User interaction (UI:N)
- Nobody has to click “OK” or open a trap file; it can work without a victim helping.
- Scope (S:U)
- Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
- Confidentiality (C:L)
- Some sensitive info could get out, but not a total data dump.
- Integrity (I:L)
- Attackers could change some data, but it’s limited—not everything goes.
- Availability (A:N)
- Service keeps running; no real outage angle.
|
CWEs
| CWE id |
Name |
|
CWE-93
|
Improper Neutralization of CRLF Sequences ('CRLF Injection') |
cvelogic
Threat Intelligence