3.11.3 / 2026-04-27
2026-05-06T08:51:39Z•d2a86800aaff4c5054533eb81fd211e05946e2625afcb3033598b504f4590718
azureadclient_secretdecompressiondenial-of-serviceghsa-8rm2-7qqf-34qmghsa-wg65-39gg-5wfjinfo-leakoauthprometheusremote-readremote-writesnappystored-xssweb-uixss
What happened
Prometheus releases (notably 3.11.3 / 3.5.3 and related 3.11.2/3.5.2) fix multiple security issues: an Azure AD remote-write information-leak that exposed OAuth client_secret via the /-/config endpoint (CVE-2026-42151), stored XSS in the web UI triggered by crafted metric names/label values (CVE-2026-40179), and snappy-compression decode/length handling flaws in remote-read/remote-write that could allow resource exhaustion or other malformed-compression abuse. The announcements credit multiple reporters and include GHSA advisories for the OAuth and snappy issues.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- d2a86800aaff4c5054533eb81fd211e05946e2625afcb3033598b504f4590718
- Enrichment time
- 2026-05-06T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.