CVE-2026-46720
HIGHCVSS v3.1: 8.2 · EPSS: 0.0033 (24.8 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 8.2 v3.1 · NVD
- EPSS
- 0.0033 (24.8 percentile) · FIRST.org
- CISA KEV
- No
- Attack conditions (CVSS vector)
- NetworkNo privilegesNo user interaction · Source: NVD Vector
- Published
- 2026-05-17 · Modified: 2026-06-19
- References
- Jump to references (3)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.