Executive brief
Mojolicious::Plugin::Statsd is a Perl library used to send application performance metrics to a Statsd monitoring server. A vulnerability in versions up to 0.04 allows attackers to inject fake or malicious monitoring data if the application processes untrusted input as a metric name or value. This could lead to corrupted analytics, false alerts, or the masking of actual system issues.
Technical details
Mojolicious::Plugin::Statsd (up to version 0.04) fails to validate or sanitize metric names and set values for control characters such as newlines (\n), colons (:), or pipes (|). Because the Statsd protocol is line-based and uses these characters as delimiters, an attacker providing untrusted input that is subsequently used in a metric can inject entirely new, unauthorized metrics into the UDP stream. This is classified as a CRLF injection (CWE-93). The issue was resolved in version 0.06 by migrating the underlying protocol handling to Net::Statsd::Tiny (v0.4.0 or later), which includes the necessary sanitization logic.
Affected products
- Mojolicious (Perl CPAN) Mojolicious::Plugin::Statsd through 0.04
Timeline
- 2026-05-21: patched: Fix committed in version 0.06 and 0.05.
- 2026-05-26: disclosed: CVE published to NVD.