216.73.216.36

CVE-2026-42154

· Published 04/05/2026 19:16 · Modified 04/05/2026 19:16

Labels: CVE-2026-42154 2026-05-04CVE-2026-42154CWE-400[email protected]

Essential information

Published
04/05/2026 19:16
Modified
04/05/2026 19:16
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
prometheus / prometheus cpe:2.3:a:prometheus:prometheus:<3.5.3:*:*:*:*:*:*:*
prometheus / prometheus cpe:2.3:a:prometheus:prometheus:<3.11.3:*:*:*:*:*:*:*

References