CVE-2026-11362
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.
The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1565.002Transmitted Data Manipulationimpact75 % - Impacto secundario
T1059Command and Scripting Interpreterexecution60 %
Inyección de métricas en etiquetas no sanitizadas (CWE-93, CWE-150) sobre servicio remoto sin autenticación (AV:N, PR:N). Permite manipular datos y potencialmente ejecutar comandos a través de métricas malformadas.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-93, CWE-150
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-11362",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-11362",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-08T18:20:03.616117Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"affectedData": [
{
"repo": "https://github.com/binary-com/dogstatsd-perl",
"vendor": "BINARY",
"product": "DataDog::DogStatsd",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "0.07"
}
],
"packageName": "DataDog-DogStatsd",
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "DataDog::DogStatsd::format_event"
},
{
"name": "DataDog::DogStatsd::event"
}
]
}
]
}
],
"published": "2026-06-05T16:16:41.277",
"references": [
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46719",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46720",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2026-46741",
"tags": [
"Third Party Advisory"
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"description": [
{
"lang": "en",
"value": "CWE-93"
},
{
"lang": "en",
"value": "CWE-150"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.\n\nDataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.\n\nThe format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)"
}
],
"lastModified": "2026-06-17T10:13:59.040",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:binary:datadog\\:\\:dogstatsd:*:*:*:*:*:perl:*:*",
"vulnerable": true,
"matchCriteriaId": "7698C317-26E6-4CC9-8811-62E53194508F",
"versionEndIncluding": "0.07"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}