Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9270— DataDog::DogStatsd versions through 0.07 for Perl allow metric injections

AI Predicted 8.6 Difficulty: Easy EPSS 0.33% · P25

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
BINARYDataDog::DogStatsd≤ 0.07affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9270

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
Source: NVD (National Vulnerability Database)
Vulnerability Description
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta variable), allowing attackers to inject metrics, especially from methods that do not restrict the data type for the value, such as set, gauge, count and histogram. The send_stats method does not validate the content of the tags, which may contain newlines, pipes and colons that allow metric injections. Note that the SYNOPSIS shows an example of passing a website form "loginName" parameter as a tag, which is unsafe.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
DataDog::DogStatsd 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DataDog::DogStatsd是DataDog公司的一个支持DogStatsD协议的Perl监控客户端库。 DataDog::DogStatsd 0.07及之前版本存在安全漏洞,该漏洞源于未正确清理输入,send_stats方法未从指标名称中删除换行符,未验证值的内容,未验证标签的内容,可能导致指标注入。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
BINARYDataDog::DogStatsd 0 ~ 0.07 -

II. Public POCs for CVE-2026-9270

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9270

登录查看更多情报信息。

Other References for CVE-2026-9270 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9270

No comments yet


Leave a comment