The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Ensure only trusted data is submitted to metrics.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-150 |
Mon, 08 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Team net\
|
|
| CPEs | cpe:2.3:a:team:net\:\:async\:\:statsd\:\:client:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Team net\
|
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Team
Team net::async::statsd::client |
|
| Vendors & Products |
Team
Team net::async::statsd::client |
Thu, 04 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Title | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-19T15:33:53.933Z
Reserved: 2026-05-16T01:26:22.806Z
Link: CVE-2026-8722
Updated: 2026-06-04T18:28:20.686Z
Status : Analyzed
Published: 2026-06-04T00:17:00.333
Modified: 2026-06-08T16:39:33.110
Link: CVE-2026-8722
No data.
OpenCVE Enrichment
Updated: 2026-06-19T21:30:17Z