Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses
Summary
| CVE | CVE-2026-45179 |
|---|---|
| State | PUBLISHED |
| Assigner | CPANSec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-10 20:16:28 UTC |
| Updated | 2026-05-10 22:16:06 UTC |
| Description | Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead. |
Risk And Classification
Problem Types: CWE-319 | CWE-319 CWE-319 Cleartext Transmission of Sensitive Information
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | RRWO | PlackMiddlewareStatsd | affected 0.9.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/robrwo/Plack-Middleware-Statsd/security/advisories/GHSA-9gwm-... | 9b29abf9-4ab0-4765-b253-1875cd9b441e | github.com | |
| www.openwall.com/lists/oss-security/2026/05/10/4 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| metacpan.org/release/RRWO/Plack-Middleware-Statsd-v0.9.0/changes | 9b29abf9-4ab0-4765-b253-1875cd9b441e | metacpan.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Upgrade to version 0.9.0 or later.
Workarounds
CNA: Use a statsd daemon on the same host or through a secure communications channel.
There are currently no legacy QID mappings associated with this CVE.