3.12.0 / 2026-05-28
2026-05-29T08:51:39Z•aef684197c2f388e4101ac30e7b783112e1e8a96c2f5db0b1151182ddfadb803
AzureADDoSOAuthSTACKITclient_secretcredentials-leakdecompressiondenial-of-serviceprometheusremote-readremote-writesecret-exposuresecurity-fixservice-discoverysnappystored-xssupgrade-recommendedweb-ui
What happened
Prometheus releases (v3.12.0 / v0.312.0 and related 3.11/3.5.x fixes) address multiple security issues: a snappy decompression/remote-write (and remote-read) limit to mitigate decompression-based DoS by rejecting snappy-compressed requests whose declared decoded length exceeds 32MB; secret exposure leaks via the /-/config endpoint affecting AzureAD remote-write (OAuth client_secret) and STACKIT service discovery; and a stored XSS in the web UI triggered by crafted metric names/labels. Two CVEs are referenced for the secret exposure (CVE-2026-42151) and the stored XSS (CVE-2026-40179). Users of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- aef684197c2f388e4101ac30e7b783112e1e8a96c2f5db0b1151182ddfadb803
- Enrichment time
- 2026-05-29T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.