oss-sec mailing list archives
CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
From: Robert Rothenberg <rrwo () cpansec org>
Date: Fri, 5 Jun 2026 15:44:34 +0100
======================================================================== CVE-2026-9270 CPAN Security Group ======================================================================== CVE ID: CVE-2026-9270 Distribution: DataDog-DogStatsd Versions: through 0.07 MetaCPAN: https://metacpan.org/dist/DataDog-DogStatsd VCS Repo: https://github.com/binary-com/dogstatsd-perl DataDog::DogStatsd versions through 0.07 for Perl allow metric injections Description ----------- DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta variable), allowing attackers to inject metrics, especially from methods that do not restrict the data type for the value, such as set, gauge, count and histogram. The send_stats method does not validate the content of the tags, which may contain newlines, pipes and colons that allow metric injections. Note that the SYNOPSIS shows an example of passing a website form "loginName" parameter as a tag, which is unsafe. Problem types ------------- - CWE-93 Improper Neutralization of CRLF Sequences - CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences Workarounds ----------- Ensure that metric names, values and tags come from trusted sources or are properly sanitised. References ---------- https://www.cve.org/CVERecord?id=CVE-2026-46741 https://www.cve.org/CVERecord?id=CVE-2026-46719 https://www.cve.org/CVERecord?id=CVE-2026-46720
Current thread:
- CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections Robert Rothenberg (Jun 05)
