CVE-2026-11373Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters such as colons or pipes, allowing metric injections.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93CWE-150

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-22); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-22: 3Mentions · 2026-06-25: 1Technical Details · 2026-06-22: 3Technical Details · 2026-06-25: 106-2206-25
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-223
Disclosure2General1
2026-06-251
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-9733: Mojolicious::Plugin::Web::Auth::OAuth2 through 0.17 for Perl have an insecure default state parameter https://www.openwall.com/lists/oss-security/2026/06/23/1 CVE-2026-11373: Net::Statsite::Client through 1.1.0 allow metric injections https://www.openwall.com/lists/oss-security/2026/06/22/4

    Post summary

    The text announces and describes two Perl CPAN package vulnerabilities, providing technical details about the weaknesses but no evidence of PoC, exploitation, patches, or false claims.

    10010267
    4.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-11373 Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of sta… https://www.cve.org/CVERecord?id=CVE-2026-11373 ----- Traducción: CVE-2026-11373 Net… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑11373, describing a metric injection flaw in Net::Statsite::Client versions up to 1.1.0, without providing proof of concept, exploit code, or mitigation steps.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-11373 Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of sta… https://www.cve.org/CVERecord?id=CVE-2026-11373

    Post summary

    CVE-2026-11373 is a metric injection vulnerability in Net::Statsite::Client versions through 1.1.0, with no PoC, exploit code, patch, or active exploitation details provided.

    00000659
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-11373 Metric Injection Vulnerability in Net::Statsite::Client P... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11373 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A brief mention of CVE-2026-11373, a metric injection flaw in Net::Statsite::Client, with links to more details but no deeper technical or exploit information.

    00000119
    4.1K followersView on X

Explore more