Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42154

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

A flaw was found in Prometheus. An unauthenticated attacker can exploit the remote read endpoint (/api/v1/read) by sending a specially crafted, small snappy-compressed payload. This payload causes a disproportionately large memory allocation, leading to memory exhaustion and a Denial of Service (DoS) by crashing the Prometheus process.

Отчет

This is an Important denial of service vulnerability in Prometheus, allowing an unauthenticated remote attacker to crash the Prometheus process. This could lead to service unavailability in Red Hat products that deploy Prometheus for monitoring, as the remote read endpoint does not properly validate snappy-compressed request lengths.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
File Integrity Operatorcompliance/openshift-compliance-must-gather-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-openscap-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-operator-bundleAffected
File Integrity Operatorcompliance/openshift-compliance-rhel8-operatorAffected
File Integrity Operatorcompliance/openshift-file-integrity-operator-bundleAffected
Network Observability Operatornetwork-observability/network-observability-ebpf-agent-rhel9Not affected
Network Observability Operatornetwork-observability/network-observability-flowlogs-pipeline-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/openshift-mcp-server-rhel9Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2466505github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
nvd
4 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
msrc
4 месяца назад

Prometheus: remote read endpoint allows denial of service via crafted snappy payload

CVSS3: 7.5
debian
4 месяца назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 7.5
github
4 месяца назад

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

7.5 High

CVSS3