PT-2026-36897 · Unknown+1 · Prometheus+1

·

CVE-2026-42154

·

Published

2026-05-04

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Prometheus versions prior to 3.5.3 Prometheus versions prior to 3.11.3
Description Prometheus is an open-source monitoring system and time series database. The remote read endpoint "/api/v1/read" fails to validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload to trigger a large heap allocation per request, which can exhaust available memory and crash the process under concurrent load.
Recommendations Update to version 3.5.3. Update to version 3.11.3.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:34357
ALSA-2026:34359
AZL-86607
BIT-PROMETHEUS-2026-42154
CLEANSTART-2026-AP95632
CLEANSTART-2026-AX33738
CLEANSTART-2026-BJ92729
CLEANSTART-2026-BX78383
CLEANSTART-2026-GZ11549
CLEANSTART-2026-IT06487
CLEANSTART-2026-LY44407
CLEANSTART-2026-MJ39387
CLEANSTART-2026-MR08661
CLEANSTART-2026-MV81821
CLEANSTART-2026-NU38786
CLEANSTART-2026-OF83437
CLEANSTART-2026-PM88731
CLEANSTART-2026-QS87161
CLEANSTART-2026-SM80424
CLEANSTART-2026-TL66481
CLEANSTART-2026-TO13966
CLEANSTART-2026-UO11850
CLEANSTART-2026-XS03563
CVE-2026-42154
GHSA-8RM2-7QQF-34QM
GO-2026-5264
OPENSUSE-SU-2026:10676-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:25039
RHSA-2026:25245
RHSA-2026:29770
RHSA-2026:34357
RHSA-2026:34359
RHSA-2026:36796
RHSA-2026:41019
RHSA-2026:53412
RHSA-2026:53413
RHSA-2026:53415
SUSE-SU-2026:2243-1
SUSE-SU-2026:2265-1
SUSE-SU-2026:2768-1
SUSE-SU-2026:2774-1

Affected Products

Prometheus
Rocky Linux