Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2026-83550

Medium priority
Needs evaluation

(A flaw was found in postgres-exporter. Due to the blank import of `net ...)

1 affected package

prometheus-postgres-exporter

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus-postgres-exporter Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-80220

Medium priority
Needs evaluation

[Unknown description]

1 affected package

prometheus-postgres-exporter

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus-postgres-exporter Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44903

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram...

1 affected package

prometheus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42154

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body...

1 affected package

prometheus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42151

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string...

1 affected package

prometheus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40179

Medium priority
Needs evaluation

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where...

1 affected package

prometheus

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-40577

Medium priority

Some fixes available 3 of 5

Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on...

1 affected package

prometheus-alertmanager

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus-alertmanager Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-26735

Low priority
Ignored

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed...

1 affected package

prometheus-blackbox-exporter

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus-blackbox-exporter — Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-46146

Medium priority
Vulnerable

Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the...

2 affected packages

prometheus, golang-github-prometheus-exporter-toolkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
prometheus Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-github-prometheus-exporter-toolkit Not affected Not affected Vulnerable Not in release Not in release
Show less packages

CVE-2022-21698

Medium priority
Needs evaluation

client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is...

1 affected package

golang-github-prometheus-client-golang

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-prometheus-client-golang Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages