CVE-2026-46741
Estado: ModificadaAlta (7.5)—
Etsy::StatsD versions through 1.002002 for Perl allow metric injections.
The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Note that the git repository contains an unreleased version with the gauge and set methods that also do not check for potential metric injections.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-93, CWE-150
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46741",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-46741",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-04T17:40:21.895127Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/sanbeg/Etsy-Statsd",
"vendor": "SANBEG",
"product": "Etsy::StatsD",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.002002"
}
],
"packageName": "Etsy-StatsD",
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "Etsy::StatsD::timing"
},
{
"name": "Etsy::StatsD::update"
},
{
"name": "Etsy::StatsD::send"
}
]
}
]
}
],
"published": "2026-06-04T17:16:32.790",
"references": [
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46719",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46720",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-93"
},
{
"lang": "en",
"value": "CWE-150"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Etsy::StatsD versions through 1.002002 for Perl allow metric injections.\n\nThe metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.\n\nNote that the git repository contains an unreleased version with the gauge and set methods that also do not check for potential metric injections."
},
{
"lang": "es",
"value": "Las versiones de Etsy::StatsD hasta la 1.002002 para Perl permiten inyecciones de métricas.\n\nLos nombres y valores de las métricas no se verifican en busca de saltos de línea, dos puntos o barras verticales. Las métricas generadas a partir de fuentes no confiables podrían inyectar métricas statsd adicionales.\n\nTenga en cuenta que el repositorio de git contiene una versión no publicada con los métodos gauge y set que tampoco verifican posibles inyecciones de métricas."
}
],
"lastModified": "2026-07-22T20:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sanbeg:etsy\\:\\:statsd:*:*:*:*:*:perl:*:*",
"vulnerable": true,
"matchCriteriaId": "BA60C24A-4BF1-499C-B029-06F93652B8EA",
"versionEndIncluding": "1.002002"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}