3.12.0-rc.0 / 2026-05-19
2026-05-20T08:51:35Z•fee2c03d022f616a376d71dbbbcea49374f6bf601cfa0a77a114d1ca9552f032
CVE-2026-40179CVE-2026-42151STACKITazure-adcredential-exposuredecompressiondenial-of-serviceprometheusreleaseremote-readremote-writesecurity-fixservice-discoverysnappystored-xssxss
What happened
Prometheus releases (notably 3.12.0-rc.0, 3.11.3/3.5.3 and related maintenance versions) address multiple security issues: a decompression-limit check was added to reject snappy-compressed Remote Write/Remote Read requests whose declared decoded length exceeds the 32MB limit (mitigates decompression-bomb DoS), fixes for secret/credential exposure in service discovery integrations (STACKIT) and AzureAD OAuth where client_secret could be exposed via the /-/config endpoint (CVE-2026-42151), and a stored XSS in the web UI via unescaped metric names/labels (CVE-2026-40179). Users should upgrade to,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- prometheus_prometheus_releases
- Record identifier
- fee2c03d022f616a376d71dbbbcea49374f6bf601cfa0a77a114d1ca9552f032
- Enrichment time
- 2026-05-20T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.