3.11.2 / 2026-04-13
2026-04-14T08:51:42Z•26e50b9b085cba185d53981e9b5e9a70ffc33828706f7aca187c707886dba24d
CVE-2026-40179disclosure-2026-04-13label-valuesmetric-namesmetrics-explorerprometheussecurity-fixstored-xsstooltipsv3.11.2v3.5.2web-uixss
What happened
Prometheus releases (notably v3.11.2 and v3.5.2) fix a stored XSS vulnerability (CVE-2026-40179) in the web UI: crafted metric names and label values can trigger execution of arbitrary JavaScript in tooltips and the metrics explorer. Upgrade to the patched releases (or later) to mitigate; the issue can lead to browser-based account/session or UI manipulation when a user views malicious metrics.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- 26e50b9b085cba185d53981e9b5e9a70ffc33828706f7aca187c707886dba24d
- Enrichment time
- 2026-04-14T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.