PT-2026-40721 · Unknown · Prometheus

Iiihaiii

+1

·

Published

2026-05-05

·

Updated

2026-05-28

·

CVE-2026-44903

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Prometheus versions 2.49.0 through 3.5.2 Prometheus versions 3.11.0 through 3.11.2
Description In the legacy web UI, which is enabled via the --enable-feature=old-ui command-line flag, the histogram heatmap chart view fails to escape label values when inserting them into the HTML for axis tick mark labels. This allows an attacker capable of injecting crafted metrics to execute JavaScript in the browser of any user viewing the metric in the heatmap chart UI.
Recommendations Update to version 3.5.3. Update to version 3.11.3. As a temporary mitigation, disable the legacy web UI by removing the --enable-feature=old-ui flag.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PROMETHEUS-2026-44903
CLEANSTART-2026-AP95632
CLEANSTART-2026-MV81821
CLEANSTART-2026-QS87161
CLEANSTART-2026-TL66481
CVE-2026-44903
GHSA-FW8G-CG8F-9J28

Affected Products

Prometheus