Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40179

Опубликовано: 15 апр. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escaping. In both the Mantine UI and old React UI, chart tooltips on the Graph page render metric names containing HTML/JavaScript without sanitization. In the old React UI, the Metric Explorer fuzzy search results use dangerouslySetInnerHTML without escaping, and heatmap cell tooltips interpolate le label values without sanitization. With Prometheus v3.x defaulting to UTF-8 metric and label name validation, characters like <, >, and " are now valid in metric names and labels. An attacker who can inject metrics via a compromised scrape target, remote write, or OTLP receiver endpoint can execute arbitrary JavaScript in the browser of any Prometheus user who views the metric in the Graph UI, potenti

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.5.2 (исключая)
cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:*
Версия от 3.6.0 (включая) до 3.11.2 (исключая)

EPSS

Процентиль: 17%
0.00259
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escaping. In both the Mantine UI and old React UI, chart tooltips on the Graph page render metric names containing HTML/JavaScript without sanitization. In the old React UI, the Metric Explorer fuzzy search results use dangerouslySetInnerHTML without escaping, and heatmap cell tooltips interpolate le label values without sanitization. With Prometheus v3.x defaulting to UTF-8 metric and label name validation, characters like <, >, and " are now valid in metric names and labels. An attacker who can inject metrics via a compromised scrape target, remote write, or OTLP receiver endpoint can execute arbitrary JavaScript in the browser of any Prometheus user who views the metric in the Graph UI, pote...

msrc
4 месяца назад

Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer

CVSS3: 6.1
debian
4 месяца назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 6.1
github
4 месяца назад

Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer

suse-cvrf
2 месяца назад

Security update 5.0.8 for Multi-Linux Manager Client Tools

EPSS

Процентиль: 17%
0.00259
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79