3.12.0-rc.0 / 2026-05-19

2026-05-20T08:51:35Zfee2c03d022f616a376d71dbbbcea49374f6bf601cfa0a77a114d1ca9552f032
CVE-2026-40179CVE-2026-42151STACKITazure-adcredential-exposuredecompressiondenial-of-serviceprometheusreleaseremote-readremote-writesecurity-fixservice-discoverysnappystored-xssxss

What happened

Prometheus releases (notably 3.12.0-rc.0, 3.11.3/3.5.3 and related maintenance versions) address multiple security issues: a decompression-limit check was added to reject snappy-compressed Remote Write/Remote Read requests whose declared decoded length exceeds the 32MB limit (mitigates decompression-bomb DoS), fixes for secret/credential exposure in service discovery integrations (STACKIT) and AzureAD OAuth where client_secret could be exposed via the /-/config endpoint (CVE-2026-42151), and a stored XSS in the web UI via unescaped metric names/labels (CVE-2026-40179). Users should upgrade to,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
prometheus_prometheus_releases
Record identifier
fee2c03d022f616a376d71dbbbcea49374f6bf601cfa0a77a114d1ca9552f032
Enrichment time
2026-05-20T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.