3.13.1 / 2026-07-10
2026-07-11T08:51:49Z•f7bf8c3f39e5bad16b18d28cd8566adb46dac7d507411dd9a2e90878f73c74bd
credentials-forwardingdependenciesgolangltspagination-tokenprometheusreleasesanitize-htmlsecrets-exposuresecuritythird-party-licensestsdbxss
What happened
Multiple Prometheus releases (notably 3.13.1/3.13.0 LTS and 3.5.5/3.5.4) include security fixes and bugfixes. Key security changes: UI dependency sanitize-html was bumped to address XSS (CVE-2026-44990 and CVE-2026-53606); prometheus/common was updated to stop forwarding credentials on redirects addressing CVE-2025-4673 and CVE-2023-45289; STACKIT SD secrets exposure via the /-/config endpoint was fixed (GHSA-39j6-789q-qxvh); and several Go dependency CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985) were patched. Other notable changes include switching rule pagination tokens to SHA-256, bunding
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- f7bf8c3f39e5bad16b18d28cd8566adb46dac7d507411dd9a2e90878f73c74bd
- Enrichment time
- 2026-07-11T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.