CVE-2026-45179Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-15: 1Technical Details · 2026-05-15: 105-15
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-45179: Plack::Middleware::Statsd before 0.9.0 may leak user IP addresses https://www.openwall.com/lists/oss-security/2026/05/10/4 CVE-2026-45180: Catalyst::Plugin::Statsd through 0.10.0 may leak session ids https://www.openwall.com/lists/oss-security/2026/05/10/5 + next tweet

    Post summary

    The tweet announces two new Perl CPAN CVEs that expose user IP addresses and session IDs, providing basic technical details but no PoC, exploit code, or active exploitation evidence.

    11030643
    4.7K followersView on X

Explore more