v3.13.0-rc.0
2026-06-20T08:51:42Z•50848e6d11868c97aed67b1e57baf6005894ddeb1132856525b0f79d54021329
azure-adcredentials-leakdecompression-limitdenial-of-servicedependency-upgradegolangopentelemetrypostcssprometheusreact-router-domrelease-notesremote-readremote-writesecret-exposuresecurity-fixservice-discoverysnappystackituivitexss
What happened
Prometheus release notes (Apr–Jun 2026) describing multiple security fixes across several 3.x releases: fixes for secrets being exposed in plaintext via the /-/config endpoint (AzureAD remote-write client_secret and STACKIT service discovery), denial-of-service mitigation by limiting snappy decompressed length for remote-read/remote-write, UI XSS fixes in the old UI, and dependency upgrades (golang.org/x/net and OpenTelemetry; mantine/UI deps like react-router-dom, vite, postcss) to address reported advisories. Releases referenced include 3.11.3, 3.12.0 (and rc), 3.5.3/3.5.4, and others; the o
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- 50848e6d11868c97aed67b1e57baf6005894ddeb1132856525b0f79d54021329
- Enrichment time
- 2026-06-20T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.