CVE-2026-11373

Source
https://cve.org/CVERecord?id=CVE-2026-11373
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11373.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11373
Published
2026-06-22T11:28:06Z
Modified
2026-08-12T03:51:16Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
Details

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.

Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.

Newlines are not removed from metric names, allowing metric injections.

Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.

Database specific
{
    "cna_assigner": "CPANSec",
    "cwe_ids": [
        "CWE-150",
        "CWE-93"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11373.json"
}
References

Affected packages

Git / github.com/JaSei/Net-Statsite-Client

Affected ranges

Type
GIT
Repo
https://github.com/JaSei/Net-Statsite-Client
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11373.json"