PT-2026-48520 · Pevans · Metrics::Any::Adapter::Dogstatsd

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-50638

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet.
Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability.
In addition, the tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injections.

Weakness Enumeration

Related Identifiers

CVE-2026-50638

Affected Products

Metrics::Any::Adapter::Dogstatsd