3.13.2 / 2026-07-29

2026-07-31T08:51:31Zc485eb3f6a9e90c93a351d5a86d2f54c466ea527f30f19cd0b49ffd9a694a9a4
CVE-2026-44990CVE-2026-53606CVE-2026-56852CVELTSPromQLPrometheusTSDBUI securityXSSdependency updategolang.org/x/textgoogle.golang.org/grpcsanitize-htmlsecurity release

What happened

Prometheus releases 3.13.0–3.13.2 and 3.5.5 include security fixes for UI cross-site scripting and dependency vulnerabilities. Version 3.13.2 updates golang.org/x/text to v0.39.0 and google.golang.org/grpc to v1.82.1; version 3.5.5 updates sanitize-html to v2.17.5 for CVE-2026-53606; and version 3.13.0 updates sanitize-html for CVE-2026-44990. The 3.13.1 and 3.13.2 releases also contain non-security TSDB and PromQL stability fixes.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
c485eb3f6a9e90c93a351d5a86d2f54c466ea527f30f19cd0b49ffd9a694a9a4
Enrichment time
2026-07-31T08:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.