PT-2026-48521 · Unknown · Metrics::Any::Adapter::Signalfx
CVE-2026-50639
·
Published
2026-06-10
·
Updated
2026-06-19
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Metrics::Any::Adapter::SignalFx versions prior to 0.04
Description
The software does not protect against metric injections. The statsd protocol and its extensions, such as dogstatsd, allow multiple metrics separated by newlines to be sent within a single packet. This issue exists because Metrics::Any::Adapter::SignalFx extends Metrics::Any::Adapter::Statsd, which shares a similar flaw. Additionally, the
labels() function fails to validate tag labels for newlines or statsd control characters, allowing these labels to be used for metric injections.Recommendations
Update to version 0.04 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Metrics::Any::Adapter::Signalfx