Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet.
Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability.
In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 10 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections. | |
| Title | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections | |
| Weaknesses | CWE-93 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-10T19:38:13.983Z
Reserved: 2026-06-05T12:07:20.886Z
Link: CVE-2026-50639
Updated: 2026-06-10T19:38:05.649Z
Status : Awaiting Analysis
Published: 2026-06-10T19:16:37.483
Modified: 2026-06-10T20:19:35.917
Link: CVE-2026-50639
No data.
OpenCVE Enrichment
Updated: 2026-06-10T21:30:36Z