PT-2026-40721 · Unknown · Prometheus
Iiihaiii
+1
·
Published
2026-05-05
·
Updated
2026-05-28
·
CVE-2026-44903
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Prometheus versions 2.49.0 through 3.5.2
Prometheus versions 3.11.0 through 3.11.2
Description
In the legacy web UI, which is enabled via the
--enable-feature=old-ui command-line flag, the histogram heatmap chart view fails to escape label values when inserting them into the HTML for axis tick mark labels. This allows an attacker capable of injecting crafted metrics to execute JavaScript in the browser of any user viewing the metric in the heatmap chart UI.Recommendations
Update to version 3.5.3.
Update to version 3.11.3.
As a temporary mitigation, disable the legacy web UI by removing the
--enable-feature=old-ui flag.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prometheus