CVE-2026-8722
בינונית 6.5
תיאור (מקור, אנגלית)
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-8/8/2026
- CWE
- CWE-93, CWE-150
מוצרים מושפעים
team: net\
קישורים
- https://www.cve.org/CVERecord?id=CVE-2026-46719 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-46720 Third Party Advisory