CVE-2026-46741

7.5 HIGH
Published: June 04, 2026 Modified: June 08, 2026
View on NVD

Description

Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that the git repository contains an unreleased version with the gauge and set methods that also do not check for potential metric injections.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://www.cve.org/CVERecord?id=CVE-2026-46719
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Third Party Advisory
https://www.cve.org/CVERecord?id=CVE-2026-46720
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Third Party Advisory

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.0%
12th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

sanbeg