3.12.0 / 2026-05-28

2026-05-29T08:51:39Zaef684197c2f388e4101ac30e7b783112e1e8a96c2f5db0b1151182ddfadb803
AzureADDoSOAuthSTACKITclient_secretcredentials-leakdecompressiondenial-of-serviceprometheusremote-readremote-writesecret-exposuresecurity-fixservice-discoverysnappystored-xssupgrade-recommendedweb-ui

What happened

Prometheus releases (v3.12.0 / v0.312.0 and related 3.11/3.5.x fixes) address multiple security issues: a snappy decompression/remote-write (and remote-read) limit to mitigate decompression-based DoS by rejecting snappy-compressed requests whose declared decoded length exceeds 32MB; secret exposure leaks via the /-/config endpoint affecting AzureAD remote-write (OAuth client_secret) and STACKIT service discovery; and a stored XSS in the web UI triggered by crafted metric names/labels. Two CVEs are referenced for the secret exposure (CVE-2026-42151) and the stored XSS (CVE-2026-40179). Users of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
aef684197c2f388e4101ac30e7b783112e1e8a96c2f5db0b1151182ddfadb803
Enrichment time
2026-05-29T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.