PT-2026-48521 · Unknown · Metrics::Any::Adapter::Signalfx

CVE-2026-50639

·

Published

2026-06-10

·

Updated

2026-06-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Metrics::Any::Adapter::SignalFx versions prior to 0.04
Description The software does not protect against metric injections. The statsd protocol and its extensions, such as dogstatsd, allow multiple metrics separated by newlines to be sent within a single packet. This issue exists because Metrics::Any::Adapter::SignalFx extends Metrics::Any::Adapter::Statsd, which shares a similar flaw. Additionally, the labels() function fails to validate tag labels for newlines or statsd control characters, allowing these labels to be used for metric injections.
Recommendations Update to version 0.04 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50639

Affected Products

Metrics::Any::Adapter::Signalfx