CVE-2026-50639
Awaiting Analysis Awaiting Analysis - Queue
Metric Injection in Metrics::Any::Adapter::SignalFx Perl Module

Publication date: 2026-06-10

Last updated on: 2026-06-10

Assigner: CPANSec

Description
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _labels function does not check tags labels newlines or statsd control characters. The labels can be used for metric injections.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-10
Last Modified
2026-06-10
Generated
2026-06-11
AI Q&A
2026-06-10
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl, where it does not protect against metric injections.

The statsd protocol and its extensions, such as dogstatsd, allow multiple metrics to be sent in a single packet separated by newlines.

Metrics::Any::Adapter::SignalFx extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability.

Specifically, the _labels function does not check for newlines or control characters in tag labels, which can be exploited to inject additional metrics.

Impact Analysis

This vulnerability can allow an attacker to perform metric injections by exploiting the lack of validation in tag labels.

By injecting malicious metrics, an attacker could potentially manipulate monitoring data, leading to inaccurate or misleading metrics.

This could affect system monitoring, alerting, and decision-making processes that rely on accurate metric data.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart