3.13.0 / 2026-07-01
2026-07-02T08:51:40Z•962d6ce8e1e37bf37f239c376d35824db0f19af25e9c4eec88673991e97976b8
CVE-2026-44990DoSLTSOpenTelemetrySTACKITXSSdependency-updatesgolang.org/x/netlicensesnpmprometheusreleaseremote-writesanitize-htmlsecret-exposuresecuritysha256snappyui
What happened
Prometheus release notes (notably 3.13.0 LTS) that include multiple security fixes and hardening changes. Key security items: UI dependency sanitize-html was bumped to remediate a cross-site scripting vulnerability (CVE-2026-44990); STACKIT service-discovery secret exposure via /-/config was fixed; remote-write now rejects snappy-compressed payloads that declare decoded lengths above 32MB to mitigate a decompression-based DoS. Additional dependency bumps (golang.org/x/net, OpenTelemetry, various UI/npm packages) address several Go and JS advisories. Other notable changes: third‑party npmLicese
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- 962d6ce8e1e37bf37f239c376d35824db0f19af25e9c4eec88673991e97976b8
- Enrichment time
- 2026-07-02T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.