CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
Robert Rothenberg 05 Jun 2026 14:44 UTC
========================================================================
CVE-2026-9270 CPAN Security Group
========================================================================
CVE ID: CVE-2026-9270
Distribution: DataDog-DogStatsd
Versions: through 0.07
MetaCPAN: https://metacpan.org/dist/DataDog-DogStatsd
VCS Repo: https://github.com/binary-com/dogstatsd-perl
DataDog::DogStatsd versions through 0.07 for Perl allow metric
injections
Description
-----------
DataDog::DogStatsd versions through 0.07 for Perl allow metric
injections.
DataDog::DogStatsd does not properly sanitise input, allowing metric
injections of data from untrusted sources.
The send_stats method does not remove newlines from metric names ($stat
variable), allowing attackers to change the metric name prefix.
The send_stats method does not validate the content of the value
($delta variable), allowing attackers to inject metrics, especially
from methods that do not restrict the data type for the value, such as
set, gauge, count and histogram.
The send_stats method does not validate the content of the tags, which
may contain newlines, pipes and colons that allow metric injections.
Note that the SYNOPSIS shows an example of passing a website form
"loginName" parameter as a tag, which is unsafe.
Problem types
-------------
- CWE-93 Improper Neutralization of CRLF Sequences
- CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
Workarounds
-----------
Ensure that metric names, values and tags come from trusted sources or
are properly sanitised.
References
----------
https://www.cve.org/CVERecord?id=CVE-2026-46741
https://www.cve.org/CVERecord?id=CVE-2026-46719
https://www.cve.org/CVERecord?id=CVE-2026-46720