๐Ÿ” CVE Alert

CVE-2026-45179

MEDIUM 5.3

Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to statsd unless configured. When configured, an HMAC signature of the IP address is logged instead.

CWE CWE-319
Vendor rrwo
Product plack::middleware::statsd
Published May 10, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for rrwo plack::middleware::statsd

Be the first to know when new medium vulnerabilities affecting rrwo plack::middleware::statsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

RRWO / Plack::Middleware::Statsd
0 < 0.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/robrwo/Plack-Middleware-Statsd/security/advisories/GHSA-9gwm-665p-w2xx metacpan.org: https://metacpan.org/release/RRWO/Plack-Middleware-Statsd-v0.9.0/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/05/10/4