3.13.2 / 2026-07-29
2026-07-31T08:51:31Z•c485eb3f6a9e90c93a351d5a86d2f54c466ea527f30f19cd0b49ffd9a694a9a4
CVE-2026-44990CVE-2026-53606CVE-2026-56852CVELTSPromQLPrometheusTSDBUI securityXSSdependency updategolang.org/x/textgoogle.golang.org/grpcsanitize-htmlsecurity release
What happened
Prometheus releases 3.13.0–3.13.2 and 3.5.5 include security fixes for UI cross-site scripting and dependency vulnerabilities. Version 3.13.2 updates golang.org/x/text to v0.39.0 and google.golang.org/grpc to v1.82.1; version 3.5.5 updates sanitize-html to v2.17.5 for CVE-2026-53606; and version 3.13.0 updates sanitize-html for CVE-2026-44990. The 3.13.1 and 3.13.2 releases also contain non-security TSDB and PromQL stability fixes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- c485eb3f6a9e90c93a351d5a86d2f54c466ea527f30f19cd0b49ffd9a694a9a4
- Enrichment time
- 2026-07-31T08:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.