Executive brief
Net::Statsd::Lite is a Perl library used to send performance and monitoring data to a Statsd server. A vulnerability in this library allows an attacker to inject fake monitoring data or manipulate existing metrics if the application processes untrusted input. This could lead to inaccurate business dashboards, false alerts, or the masking of actual system issues.
Technical details
A CRLF and delimiter injection vulnerability exists in the Net::Statsd::Lite Perl module through version 0.10.0. The 'set_add' method fails to sanitize input for newlines (\n), colons (:), or pipes (|), which are control characters in the Statsd protocol. If an application passes untrusted data to this method, a remote attacker can inject additional, arbitrary metrics into the UDP stream sent to the Statsd server. This is classified as CWE-93 (Improper Neutralization of CRLF Sequences). The issue is addressed in version 0.10.1.
Affected products
- Perl CPAN Net::Statsd::Lite through 0.10.0
Timeline
- 2026-05-18: advisory: CVE-2026-8788 published by NVD
- 2026-05-18: patched: Version 0.10.1 released to address the injection vulnerability