Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses.

If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked.

Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.

Project Subscriptions

Vendors Products
Plack::middleware::statsd Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 0.9.0 or later.


Workaround

Use a statsd daemon on the same host or through a secure communications channel.

History

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Rrwo
Rrwo plack::middleware::statsd
Vendors & Products Rrwo
Rrwo plack::middleware::statsd

Sun, 10 May 2026 22:30:00 +0000

Type Values Removed Values Added
References

Sun, 10 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.
Title Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
Weaknesses CWE-319
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-05-12T13:47:21.884Z

Reserved: 2026-05-09T18:57:17.867Z

Link: CVE-2026-45179

cve-icon Vulnrichment

Updated: 2026-05-10T21:17:03.221Z

cve-icon NVD

Status : Deferred

Published: 2026-05-10T20:16:28.967

Modified: 2026-05-12T16:48:58.260

Link: CVE-2026-45179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T16:15:19Z

Weaknesses