216.73.217.24

CVE-2026-44903

· Published 26/05/2026 22:16 · Modified 26/05/2026 22:16

Labels: CVE-2026-44903 2026-05-26CVE-2026-44903CWE-79[email protected]

Essential information

Published
26/05/2026 22:16
Modified
26/05/2026 22:16
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An attacker who can inject crafted metrics can execute JavaScript in the browser of any Prometheus user who views the metric in the heatmap chart UI. This vulnerability is fixed in 3.5.3 and 3.11.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
prometheus / prometheus cpe:2.3:a:prometheus:prometheus:2.49.0-3.5.2:*:*:*:*:*:*:*
prometheus / prometheus cpe:2.3:a:prometheus:prometheus:3.11.3:*:*:*:*:*:*:*

References