3.13.1 / 2026-07-10

2026-07-11T08:51:49Zf7bf8c3f39e5bad16b18d28cd8566adb46dac7d507411dd9a2e90878f73c74bd
credentials-forwardingdependenciesgolangltspagination-tokenprometheusreleasesanitize-htmlsecrets-exposuresecuritythird-party-licensestsdbxss

What happened

Multiple Prometheus releases (notably 3.13.1/3.13.0 LTS and 3.5.5/3.5.4) include security fixes and bugfixes. Key security changes: UI dependency sanitize-html was bumped to address XSS (CVE-2026-44990 and CVE-2026-53606); prometheus/common was updated to stop forwarding credentials on redirects addressing CVE-2025-4673 and CVE-2023-45289; STACKIT SD secrets exposure via the /-/config endpoint was fixed (GHSA-39j6-789q-qxvh); and several Go dependency CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985) were patched. Other notable changes include switching rule pagination tokens to SHA-256, bunding

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
f7bf8c3f39e5bad16b18d28cd8566adb46dac7d507411dd9a2e90878f73c74bd
Enrichment time
2026-07-11T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.