3.11.2 / 2026-04-13

2026-04-14T08:51:42Z26e50b9b085cba185d53981e9b5e9a70ffc33828706f7aca187c707886dba24d
CVE-2026-40179disclosure-2026-04-13label-valuesmetric-namesmetrics-explorerprometheussecurity-fixstored-xsstooltipsv3.11.2v3.5.2web-uixss

What happened

Prometheus releases (notably v3.11.2 and v3.5.2) fix a stored XSS vulnerability (CVE-2026-40179) in the web UI: crafted metric names and label values can trigger execution of arbitrary JavaScript in tooltips and the metrics explorer. Upgrade to the patched releases (or later) to mitigate; the issue can lead to browser-based account/session or UI manipulation when a user views malicious metrics.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
26e50b9b085cba185d53981e9b5e9a70ffc33828706f7aca187c707886dba24d
Enrichment time
2026-04-14T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 3.11.2 / 2026-04-13 · Baitaphish