DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.
The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.) | |
| Title | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags | |
| Weaknesses | CWE-150 CWE-93 |
|
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-05T14:50:12.176Z
Reserved: 2026-06-05T11:42:59.357Z
Link: CVE-2026-11362
No data.
Status : Received
Published: 2026-06-05T16:16:41.277
Modified: 2026-06-05T16:16:41.277
Link: CVE-2026-11362
No data.
OpenCVE Enrichment
No data.