Количество 9
Количество 9
GHSA-8rm2-7qqf-34qm
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42154
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
CVE-2026-42154
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
CVE-2026-42154
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
CVE-2026-42154
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42154
Prometheus is an open-source monitoring system and time series databas ...
RLSA-2026:34359
Important: opentelemetry-collector security update
RLSA-2026:34357
Important: opentelemetry-collector security update
SUSE-SU-2026:2243-1
Security update 5.0.8 for Multi-Linux Manager Client Tools
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8rm2-7qqf-34qm Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-42154 Prometheus is an open-source monitoring system and time series databas ... | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
RLSA-2026:34359 Important: opentelemetry-collector security update | 26 дней назад | |||
RLSA-2026:34357 Important: opentelemetry-collector security update | 24 дня назад | |||
SUSE-SU-2026:2243-1 Security update 5.0.8 for Multi-Linux Manager Client Tools | около 2 месяцев назад |
Уязвимостей на страницу