CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allow metric injections Robert Rothenberg 05 Jun 2026 14:44 UTC

========================================================================
CVE-2026-9270                                        CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-9270
   Distribution:  DataDog-DogStatsd
       Versions:  through 0.07

       MetaCPAN:  https://metacpan.org/dist/DataDog-DogStatsd
       VCS Repo:  https://github.com/binary-com/dogstatsd-perl

DataDog::DogStatsd versions through 0.07 for Perl allow metric
injections

Description
-----------
DataDog::DogStatsd versions through 0.07 for Perl allow metric
injections.

DataDog::DogStatsd does not properly sanitise input, allowing metric
injections of data from untrusted sources.

The send_stats method does not remove newlines from metric names ($stat
variable), allowing attackers to change the metric name prefix.

The send_stats method does not validate the content of the value
($delta variable), allowing attackers to inject metrics, especially
from methods that do not restrict the data type for the value, such as
set, gauge, count and histogram.

The send_stats method does not validate the content of the tags, which
may contain newlines, pipes and colons that allow metric injections.

Note that the SYNOPSIS shows an example of passing a website form
"loginName" parameter as a tag, which is unsafe.

Problem types
-------------
- CWE-93 Improper Neutralization of CRLF Sequences
- CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences

Workarounds
-----------
Ensure that metric names, values and tags come from trusted sources or
are properly sanitised.

References
----------
https://www.cve.org/CVERecord?id=CVE-2026-46741
https://www.cve.org/CVERecord?id=CVE-2026-46719
https://www.cve.org/CVERecord?id=CVE-2026-46720