Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42154

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

A flaw was found in Prometheus. An unauthenticated attacker can exploit the remote read endpoint (/api/v1/read) by sending a specially crafted, small snappy-compressed payload. This payload causes a disproportionately large memory allocation, leading to memory exhaustion and a Denial of Service (DoS) by crashing the Prometheus process.

Отчет

This is an Important denial of service vulnerability in Prometheus, allowing an unauthenticated remote attacker to crash the Prometheus process. This could lead to service unavailability in Red Hat products that deploy Prometheus for monitoring, as the remote read endpoint does not properly validate snappy-compressed request lengths.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
File Integrity Operatorcompliance/openshift-compliance-must-gather-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-openscap-rhel8Affected
File Integrity Operatorcompliance/openshift-compliance-operator-bundleAffected
File Integrity Operatorcompliance/openshift-compliance-rhel8-operatorAffected
File Integrity Operatorcompliance/openshift-file-integrity-operator-bundleAffected
File Integrity Operatorcompliance/openshift-file-integrity-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-ebpf-agent-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2466505github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
nvd
3 месяца назад

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS3: 7.5
msrc
3 месяца назад

Prometheus: remote read endpoint allows denial of service via crafted snappy payload

CVSS3: 7.5
debian
3 месяца назад

Prometheus is an open-source monitoring system and time series databas ...

CVSS3: 7.5
github
3 месяца назад

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

7.5 High

CVSS3