3.13.0 / 2026-07-01

2026-07-02T08:51:40Z962d6ce8e1e37bf37f239c376d35824db0f19af25e9c4eec88673991e97976b8
CVE-2026-44990DoSLTSOpenTelemetrySTACKITXSSdependency-updatesgolang.org/x/netlicensesnpmprometheusreleaseremote-writesanitize-htmlsecret-exposuresecuritysha256snappyui

What happened

Prometheus release notes (notably 3.13.0 LTS) that include multiple security fixes and hardening changes. Key security items: UI dependency sanitize-html was bumped to remediate a cross-site scripting vulnerability (CVE-2026-44990); STACKIT service-discovery secret exposure via /-/config was fixed; remote-write now rejects snappy-compressed payloads that declare decoded lengths above 32MB to mitigate a decompression-based DoS. Additional dependency bumps (golang.org/x/net, OpenTelemetry, various UI/npm packages) address several Go and JS advisories. Other notable changes: third‑party npmLicese

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
962d6ce8e1e37bf37f239c376d35824db0f19af25e9c4eec88673991e97976b8
Enrichment time
2026-07-02T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.