CVE-2026-46719Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93CWE-150

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-16: 1Mentions · 2026-05-17: 2Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-20: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-17: 2Technical Details · 2026-05-20: 105-1605-1705-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-161
Disclosure1
2026-05-172
Disclosure2
2026-05-201
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-46719,CVE-2026-8788: Net::Statsd::Lite through 0.10.0 allowed metric injections https://www.openwall.com/lists/oss-security/2026/05/16/9 and https://www.openwall.com/lists/oss-security/2026/05/18/1 CVE-2026-46720: Net::Statsd::Tiny before 0.3.8 allowed metric injections https://www.openwall.com/lists/oss-security/2026/05/17/2

    Post summary

    The post announces two CVEs affecting Perl CPAN modules, provides technical details of the metric injection flaw, and includes links to discussions but does not mention patches, PoC code, or active exploitation.

    1000045
    4.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46719 Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from u… https://www.cve.org/CVERecord?id=CVE-2026-46719 ----- Traducción: CVE-2026-46719 Net… http://infoflow.cloud`

    Post summary

    The post discloses a metric injection vulnerability in Net::Statsd::Lite versions before 0.9.0, describing the lack of input validation for metric names.

    0000036
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-46719 Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from u… https://www.cve.org/CVERecord?id=CVE-2026-46719

    Post summary

    CVE-2026-46719 involves metric injection in Net::Statsd::Lite prior to 0.9.0 due to unvalidated metric names, with no PoC, exploit, patch, or active exploitation mentioned.

    00000285
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-46719 Metric Injection Vulnerability in Net::Statsd::Lite for Perl Before 0.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46719

    Post summary

    The text announces a metric injection vulnerability in Net::Statsd::Lite prior to version 0.9.0, offering technical detail but no exploit or patch information.

    0000070
    4.0K followersView on X

Explore more