Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cosimo

Researcher fromCPANSec
#48423of 53,612
5.3Total CVSS
Vulnerabilities · 1
PT-2026-46264
5.3
2026-06-04
Cpan · Net::Statsd · CVE-2026-46739
**Name of the Vulnerable Software and Affected Versions** Net::Statsd versions prior to 0.13 **Description** Net::Statsd for Perl allows metric injections because metric names are not validated for newlines, colons, or pipes. This allows metrics generated from untrusted sources to inject additional statsd metrics. Specifically, the `update stats()` function (used for updating counters) and the `gauge()` function do not verify that values are numeric, which would otherwise prevent such injections. **Recommendations** Update to version 0.13 or later.