Metric Injection Vulnerability in Net::Statsd::Lite by RRWO
CVE-2026-46719

6.5MEDIUM

Key Information:

Vendor

Rrwo

Vendor
CVE Published:
16 May 2026

What is CVE-2026-46719?

The Net::Statsd::Lite library for Perl prior to version 0.9.0 is susceptible to a metric injection vulnerability. This flaw arises from a failure to validate metric names for the presence of newlines, colons, or pipes. Consequently, metrics sourced from untrusted origins have the potential to inject additional StatsD metrics, compromising the integrity of the metrics framework. Users relying on this library should upgrade to the latest version to mitigate the risks associated with this issue.

Affected Version(s)

Net::Statsd::Lite 0 < 0.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.