Junglewise Threat Intelligence

CVE-2026-8722: Perl Net::Async::Statsd::Client metric injection via CRLF sequences

CVE-2026-8722 · Severity: info · CVSS 5.3 · Published 2026-06-04

Vendors: Perl CPAN, CPAN.

Executive brief

Net::Async::Statsd::Client is a Perl library used to send performance metrics to monitoring systems. A security flaw allows attackers to inject fake or malicious data into these monitoring systems if the application uses untrusted input to name its metrics. This could lead to inaccurate business dashboards, false alerts, or the corruption of historical performance data.

Technical details

The Net::Async::Statsd::Client library fails to sanitize metric names for control characters such as newlines (\n), colons (:), or pipes (|). This vulnerability, classified as a CRLF injection (CWE-93), allows an attacker who can influence metric names to inject additional, unauthorized StatsD protocol commands. Because StatsD is a line-based protocol, injecting a newline allows the attacker to start a new metric entry entirely. This can be exploited remotely if the application incorporates user-provided strings into metric names without prior validation. As of the advisory date, versions up to 0.005 are confirmed to be affected.

Affected products

  • Perl CPAN Net::Async::Statsd::Client through 0.005

Timeline

  • 2026-06-04: advisory: NVD published the vulnerability record

References