CVE-2026-11362criticalCWE-150CWE-93

CVE-2026-11362: fallo crítico en BINARY DataDog::DogStatsd

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags

Publicada el · Actualizada el

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 0.4%
probabilidad de explotación
0.4%top 63% de las CVE
explotación observada
noninguna fuente lo reporta
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
BINARY · DataDog::DogStatsd
CVEs relacionadas — BINARY DataDog::DogStatsd

En el mismo producto, de las más peligrosas a las menos.