Junglewise Threat Intelligence

CVE-2026-46740: Mojolicious::Plugin::Statsd metric injection via CRLF sequences

CVE-2026-46740 · Severity: info · CVSS 0 · Published 2026-05-26

Executive brief

Mojolicious::Plugin::Statsd is a Perl library used to send application performance metrics to a Statsd monitoring server. A vulnerability in versions up to 0.04 allows attackers to inject fake or malicious monitoring data if the application processes untrusted input as a metric name or value. This could lead to corrupted analytics, false alerts, or the masking of actual system issues.

Technical details

Mojolicious::Plugin::Statsd (up to version 0.04) fails to validate or sanitize metric names and set values for control characters such as newlines (\n), colons (:), or pipes (|). Because the Statsd protocol is line-based and uses these characters as delimiters, an attacker providing untrusted input that is subsequently used in a metric can inject entirely new, unauthorized metrics into the UDP stream. This is classified as a CRLF injection (CWE-93). The issue was resolved in version 0.06 by migrating the underlying protocol handling to Net::Statsd::Tiny (v0.4.0 or later), which includes the necessary sanitization logic.

Affected products

  • Mojolicious (Perl CPAN) Mojolicious::Plugin::Statsd through 0.04

Timeline

  • 2026-05-21: patched: Fix committed in version 0.06 and 0.05.
  • 2026-05-26: disclosed: CVE published to NVD.

References