3.13.2 / 2026-07-29
2026-08-01T08:51:31Z•239218945bfdbcee44742fca1bd51122d2f361f8bd1d37a6a4dc9860a7eb4df5
CVE-2026-44990CVE-2026-53606CVE-2026-56852GoLTSPromQLPrometheusTSDBUIXSScross-site-scriptingdependency-updategRPCgolang.org/x/textrelease-notessanitize-htmlsecurity-update
What happened
Prometheus release feed reporting security fixes across the 3.13.x and 3.5.x branches. Prometheus 3.13.2 updates golang.org/x/text to 0.39.0 for CVE-2026-56852 and google.golang.org/grpc to 1.82.1 for GHSA-hrxh-6v49-42gf. Prometheus 3.5.5 updates sanitize-html to 2.17.5 for CVE-2026-53606, while 3.13.0 fixes a sanitize-html cross-site scripting vulnerability tracked as CVE-2026-44990. Releases also include stability and data-query bug fixes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- 239218945bfdbcee44742fca1bd51122d2f361f8bd1d37a6a4dc9860a7eb4df5
- Enrichment time
- 2026-08-01T08:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.