PT-2026-48520 · Cpan · Metrics::Any::Adapter::Dogstatsd

CVE-2026-50638

·

Published

2026-06-10

·

Updated

2026-06-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Metrics::Any::Adapter::DogStatsd versions prior to 0.04
Description The software does not protect against metric injections. The statsd protocol and its extensions, such as dogstatsd, allow multiple metrics to be sent per packet when separated by newlines. This issue exists because the software extends Metrics::Any::Adapter::Statsd, which shares a similar flaw. Additionally, the tags() function fails to validate tags for newlines or statsd control characters, allowing tags to be used for metric injections.
Recommendations Update to version 0.04 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50638

Affected Products

Metrics::Any::Adapter::Dogstatsd