3.11.3 / 2026-04-27

2026-05-06T08:51:39Zd2a86800aaff4c5054533eb81fd211e05946e2625afcb3033598b504f4590718
azureadclient_secretdecompressiondenial-of-serviceghsa-8rm2-7qqf-34qmghsa-wg65-39gg-5wfjinfo-leakoauthprometheusremote-readremote-writesnappystored-xssweb-uixss

What happened

Prometheus releases (notably 3.11.3 / 3.5.3 and related 3.11.2/3.5.2) fix multiple security issues: an Azure AD remote-write information-leak that exposed OAuth client_secret via the /-/config endpoint (CVE-2026-42151), stored XSS in the web UI triggered by crafted metric names/label values (CVE-2026-40179), and snappy-compression decode/length handling flaws in remote-read/remote-write that could allow resource exhaustion or other malformed-compression abuse. The announcements credit multiple reporters and include GHSA advisories for the OAuth and snappy issues.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
d2a86800aaff4c5054533eb81fd211e05946e2625afcb3033598b504f4590718
Enrichment time
2026-05-06T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.