3.12.0 / 2026-05-28
2026-05-30T08:51:40Z•ec1b4384657ca1f765934e95e55c7c2b4f96c0000351338c8f475e508dcd9ff0
STACKITazureaddecompression-limitdenial-of-serviceoauthperformanceprometheuspromqlremote-readremote-writesecret-exposuresecurity-fixservice-discoverysnappystored-xsstsdbuiv3.12.0
What happened
Prometheus release v3.12.0 (May 2026) addresses multiple security issues and other enhancements. Key security fixes: a denial-of-service mitigation in remote-write by rejecting snappy-compressed requests whose declared decoded length exceeds the 32MB limit (prevents decompression amplification), and a secret-exposure fix for the STACKIT service discovery backend. The project also recently fixed related issues in prior 3.11.x/3.5.x releases (including an AzureAD OAuth client_secret exposure - CVE-2026-42151 - and a stored XSS in the UI - CVE-2026-40179). Users should upgrade to the patched Prom
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- ec1b4384657ca1f765934e95e55c7c2b4f96c0000351338c8f475e508dcd9ff0
- Enrichment time
- 2026-05-30T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.