<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Prometheus (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/prometheus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/prometheus-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Prometheus (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-44902 – opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a sin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44902</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44902</strong></p>
  <p>opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42154 – Prometheus is an open-source monitoring system and time series database. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42154</guid>
    <pubDate>Mon, 04 May 2026 19:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42154</strong></p>
  <p>Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust av…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42151 – Prometheus is an open-source monitoring system and time series database. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42151</guid>
    <pubDate>Mon, 04 May 2026 19:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42151</strong></p>
  <p>Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Az…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62188 – An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62188</guid>
    <pubDate>Thu, 09 Apr 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62188</strong></p>
  <p>An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.  This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.   This issue affects Apache DolphinScheduler versions 3.1.*.   Users are recommended to upgrade to:          *  version ≥ 3.2.0 if using 3.1.x       As a temporary workaroun…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24892 – openITCOCKPIT is an open source monitoring tool built for different monitoring e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24892</guid>
    <pubDate>Fri, 20 Feb 2026 21:19:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24892</strong></p>
  <p>openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from attacker-influenced application state is unserialized without restricting allowed classes. Although…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24891 – openITCOCKPIT is an open source monitoring tool built for different monitoring e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24891</guid>
    <pubDate>Fri, 20 Feb 2026 18:25:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24891</strong></p>
  <p>openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads without enforcing class restrictions or validating data origin. While the intended de…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26069 – Scraparr is a Prometheus Exporter for various components of the *arr Suite. From...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26069</guid>
    <pubDate>Thu, 12 Feb 2026 22:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26069</strong></p>
  <p>Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled, the exporter exposed the configured Readarr API key as the alias metric label value. Users were affected only if all of the following conditions are met, Readarr scraping feature was enabled and no alias configured, the exporter’s /metrics endpoint…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50608 – An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50608</guid>
    <pubDate>Tue, 18 Feb 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50608</strong></p>
  <p>An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL poi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24030 – Envoy Gateway is an open source project for managing Envoy Proxy as a standalone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24030</guid>
    <pubDate>Thu, 23 Jan 2025 04:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24030</strong></p>
  <p>Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy config…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-419</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34046 – The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpTh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34046</guid>
    <pubDate>Tue, 30 Apr 2024 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34046</strong></p>
  <p>The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34045 – The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpTh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34045</guid>
    <pubDate>Tue, 30 Apr 2024 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34045</strong></p>
  <p>The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39337 – Hertzbeat is an open source, real-time monitoring system with custom-monitoring,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39337</guid>
    <pubDate>Fri, 22 Dec 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39337</strong></p>
  <p>Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke interfaces without authorization. Version 1.2.1 contains a patch for this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48796 – Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48796</guid>
    <pubDate>Fri, 24 Nov 2023 08:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48796</strong></p>
  <p>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.  The information exposed to unauthorized actors may include sensitive data such as database credentials.  Users who can't upgrade to the fixed version can also set environment variable `MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus` to workaround this, or add the following se…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38994 – The 'check_univention_joinstatus' prometheus monitoring script (and other script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38994</guid>
    <pubDate>Tue, 31 Oct 2023 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38994</strong></p>
  <p>The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not allow local ssh access for regular users.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40577 – Alertmanager handles alerts sent by client applications such as the Prometheus s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40577</guid>
    <pubDate>Fri, 25 Aug 2023 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40577</strong></p>
  <p>Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27591 – Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27591</guid>
    <pubDate>Fri, 17 Mar 2023 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27591</strong></p>
  <p>Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default). A patch is available in Miniflux 2.0.43. As a workaround, set `METRICS_COLLECTOR` to `false` (default) or run Minif…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21698 – client_golang is the instrumentation library for Go applications in Prometheus, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21698</guid>
    <pubDate>Tue, 15 Feb 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21698</strong></p>
  <p>client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14602 – An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14602</guid>
    <pubDate>Fri, 27 Jul 2018 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14602</strong></p>
  <p>An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-1211 – Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-1211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-1211</guid>
    <pubDate>Tue, 12 Nov 2002 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-1211</strong></p>
  <p>Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-1211">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
