| CVE-2026-42154 |
BDSA-2026-9055 |
High |
May 04, 2026 |
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) do
more...
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
less...
|
v0.313.1, v0.305.5, v0.313.0, v0.305.4, v0.311.3, v0.305.3, v0.311.2, v3.11.2, v0.305.2, v3.5.2
|
| CVE-2019-3826 |
|
Medium |
Mar 26, 2019 |
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an auth
more...
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
less...
|
v0.313.1, v0.305.5, v0.313.0, v0.305.4, v0.311.3, v0.305.3, v0.311.2, v0.305.2, v0.311.1, v0.311.0
|