CVE-2026-11362 PUBLISHED

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags

Assigner: CPANSec
Reserved: 05.06.2026 Published: 05.06.2026 Updated: 05.06.2026

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.

DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.

The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)

Product Status

Vendor BINARY
Product DataDog::DogStatsd
Versions Default: unaffected
  • affected from 0 to 0.07 (incl.)

Workarounds

Ensure that metric names, values and tags come from trusted sources or are properly sanitised.

References

Problem Types

  • CWE-93 Improper Neutralization of CRLF Sequences CWE
  • CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences CWE