VYPR
Vendor

Prometheus

Products
5
CVEs
11
Across products
12
Status
Private

Products

5

Recent CVEs

11
  • CVE-2023-40577HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue…

  • CVE-2023-26735HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.01

    blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third parties because authentication can be…

  • CVE-2021-29622MedMay 19, 2021
    risk 0.44cvss 6.5epss 0.20

    Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an…

  • CVE-2026-42154HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.01

    Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated…

  • CVE-2026-42151HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type…

  • CVE-2020-16248MedAug 9, 2020
    risk 0.38cvss 5.8epss 0.03

    Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

  • CVE-2026-44903MedMay 26, 2026
    risk 0.33cvss 6.1epss 0.00

    Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values…

  • CVE-2026-40179MedApr 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into…

  • CVE-2022-46146MedNov 29, 2022
    risk 0.33cvss 6.2epss 0.01

    Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and…

  • CVE-2019-3826MedMar 26, 2019
    risk 0.33cvss 6.1epss 0.03

    A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary…

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…