Vulnerability Description
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- http://armon.github.io/statsite
- https://metacpan.org/release/JASEI/Net-Statsite-Client-1.1.0/view/lib/Net/Statsi
- https://security.metacpan.org/patches/N/Net-Statsite-Client/1.1.0/CVE-2026-11373
- https://www.cve.org/CVERecord?id=CVE-2026-46719
- https://www.cve.org/CVERecord?id=CVE-2026-46720
- https://www.cve.org/CVERecord?id=CVE-2026-46739
FAQ
What is CVE-2026-11373?
CVE-2026-11373 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed fro...
How severe is CVE-2026-11373?
CVE-2026-11373 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-11373?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.