Prometheus monitoring software contains a vulnerability that allows attackers to redirect users to arbitrary external websites through specially crafted URLs, which could be exploited for phishing attacks.
Prometheus
Prometheus28.05.2026
bewährt — keine offenen Regressionen, etabliert · 0 open bugs, 0 Regressions
Upgrade assessment
SicherheitsrelevantZeitnah aktualisieren
Derived automatically from release, repo and CVE data — no judgment by a language model.
A vulnerability in Prometheus allows attackers to bypass authentication if they have access to hashed passwords by manipulating the internal cache used for password verification.
A security vulnerability in the Prometheus web interface allows attackers to inject malicious JavaScript code through crafted metric names, which then executes in users' browsers when they hover over charts or browse metrics.
A vulnerability in Prometheus exposes Azure AD OAuth secrets in plaintext through an HTTP API when users can access the configuration endpoint.
A vulnerability in Prometheus allows attackers to cause excessive memory allocation and crash the service by sending crafted requests to the remote read endpoint.
A security vulnerability in Prometheus allows attackers to inject malicious JavaScript code into the legacy web interface when they can inject crafted metrics, potentially enabling data theft or server shutdown.
Prometheus v3.12.0 fixes two security vulnerabilities (DoS in remote-write and secret leak in STACKIT SD), introduces experimental PromQL functions and improves TSDB performance
Prometheus v3.12.0-rc.0 fixes two security vulnerabilities (DoS in remote-write and secret leak in STACKIT SD), introduces experimental PromQL functions and improves TSDB performance
Security update fixes multiple vulnerabilities including OAuth secrets exposure, snappy decompression issues and XSS attacks
Security update fixes three vulnerabilities: OAuth secrets in plaintext, snappy decompression issues, and XSS in the old user interface
Security update fixes Stored XSS vulnerability in web UI and improves regex performance
Security update fixes Stored XSS vulnerability in web UI and adds Consul Service Discovery improvements
Fixes startup failure when using OTLP HTTP tracing with insecure connection
Prometheus v3.11.0 introduces new AWS service discovery roles, experimental histogram features and PromQL operators, fixes critical bugs in alerting and TSDB, and deprecates some Hetzner SD labels
Prometheus v3.11.0-rc.0 introduces new AWS service discovery roles, experimental histogram features and PromQL operators, fixes critical bugs in alerting and TSDB, and deprecates some Hetzner SD labels
Prometheus 3.10.0 introduces distroless Docker images, adds PromQL fill() functions and OpenAPI specification, fixes multiple bugs and improves performance
Prometheus 3.10.0-rc.1 introduces distroless Docker images, adds PromQL fill() functions and OpenAPI specification, and fixes various bugs in PromQL and TSDB
Maintenance release without code changes featuring updated dependencies for Docker library and Go version
Native Histograms are no longer experimental, feature flag removed and replaced with configuration option
Fixes critical bugs in agent startup crashes and scraping relabel functionality
Native Histograms are no longer experimental, feature flag removed and replaced with configuration option
Fixes incorrect response headers in Remote Write receiver that caused false partial error logs and metrics in Prometheus senders
Native Histograms introduced as stable feature but require explicit activation via scrape_native_histograms configuration with changes to feature flag behavior
Remote-write 2 specification updated to version 2.0-rc.4 with renaming of 'created timestamp' to 'start timestamp' and added OAuth2 JWT-Bearer grant-type support
Native Histograms introduced as stable feature but require explicit activation via scrape_native_histogram configuration setting
Bugfixes for UI redirect behavior, native histogram federation, promtool configuration checking, and remote-write deadlock
Bug fixes for AWS Service Discovery credentials handling, relabeling validation, and PromQL parsing with special metric and label names
Fixed OTLP label translation for OTel attribute names with underscores, reverting breaking changes introduced in version 3.7.0
Prometheus 3.7.0 contains a critical bug in the OTLP endpoint that breaks translation of OpenTelemetry attribute names starting with underscore
Prometheus v3.7.0-rc.0 introduces experimental PromQL functions, improves native histogram support and deprecates several remote-write metrics
Prometheus v3.6.0 adds new PromQL functions, TSDB block metadata API and template functions, improves OTLP support and fixes several bugs including memory corruption and panics
Added new metric prometheus_tsdb_head_stale_series to track stale time series in the Head block
Prometheus v3.6.0-rc.0 adds new PromQL functions, API endpoints and OTLP enhancements along with various bugfixes for PromQL, TSDB and Discovery
Prometheus v3.5.0 LTS release with new experimental PromQL functions, STACKIT Cloud service discovery, performance improvements and various bugfixes
Prometheus v3.5.0-rc.1 introduces new experimental PromQL functions, STACKIT Cloud service discovery, and various performance improvements
Prometheus 3.5.0-rc.0 release candidate with new experimental PromQL functions, OTLP improvements, STACKIT Cloud service discovery and various performance optimizations