DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.
The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Ensure that metric names, values and tags come from trusted sources or are properly sanitised.
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Binary
Binary datadog::dogstatsd |
|
| Vendors & Products |
Binary
Binary datadog::dogstatsd |
Fri, 05 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.) | |
| Title | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags | |
| Weaknesses | CWE-150 CWE-93 |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-08T18:20:09.533Z
Reserved: 2026-06-05T11:42:59.357Z
Link: CVE-2026-11362
Updated: 2026-06-08T18:19:50.308Z
Status : Undergoing Analysis
Published: 2026-06-05T16:16:41.277
Modified: 2026-06-08T19:16:41.070
Link: CVE-2026-11362
No data.
OpenCVE Enrichment
Updated: 2026-06-08T21:00:14Z