3.13.2 / 2026-07-29

2026-08-01T08:51:31Z239218945bfdbcee44742fca1bd51122d2f361f8bd1d37a6a4dc9860a7eb4df5
CVE-2026-44990CVE-2026-53606CVE-2026-56852GoLTSPromQLPrometheusTSDBUIXSScross-site-scriptingdependency-updategRPCgolang.org/x/textrelease-notessanitize-htmlsecurity-update

What happened

Prometheus release feed reporting security fixes across the 3.13.x and 3.5.x branches. Prometheus 3.13.2 updates golang.org/x/text to 0.39.0 for CVE-2026-56852 and google.golang.org/grpc to 1.82.1 for GHSA-hrxh-6v49-42gf. Prometheus 3.5.5 updates sanitize-html to 2.17.5 for CVE-2026-53606, while 3.13.0 fixes a sanitize-html cross-site scripting vulnerability tracked as CVE-2026-44990. Releases also include stability and data-query bug fixes.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
239218945bfdbcee44742fca1bd51122d2f361f8bd1d37a6a4dc9860a7eb4df5
Enrichment time
2026-08-01T08:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 3.13.2 / 2026-07-29 · Baitaphish