PT-2026-40721 · Unknown · Prometheus

·

CVE-2026-44903

·

Published

2026-05-05

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prometheus versions 2.49.0 through 3.5.2 Prometheus versions 3.11.0 through 3.11.2
Description In the legacy web UI, which is enabled via the --enable-feature=old-ui command-line flag, the histogram heatmap chart view fails to escape label values when inserting them into the HTML for axis tick mark labels. This allows an attacker capable of injecting crafted metrics to execute JavaScript in the browser of any user viewing the metric in the heatmap chart UI.
Recommendations Update to version 3.5.3. Update to version 3.11.3. As a temporary mitigation, disable the legacy web UI by removing the --enable-feature=old-ui flag.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PROMETHEUS-2026-44903
CLEANSTART-2026-AP95632
CLEANSTART-2026-BJ92729
CLEANSTART-2026-BX78383
CLEANSTART-2026-GX27419
CLEANSTART-2026-GZ11549
CLEANSTART-2026-IE49312
CLEANSTART-2026-IT06487
CLEANSTART-2026-LC55153
CLEANSTART-2026-LY44407
CLEANSTART-2026-MJ39387
CLEANSTART-2026-MR08661
CLEANSTART-2026-MV81821
CLEANSTART-2026-NU38786
CLEANSTART-2026-OF83437
CLEANSTART-2026-QS87161
CLEANSTART-2026-SM80424
CLEANSTART-2026-TL66481
CLEANSTART-2026-TO13966
CLEANSTART-2026-UO11850
CLEANSTART-2026-XS03563
CLEANSTART-2026-ZZ38071
CVE-2026-44903
GHSA-FW8G-CG8F-9J28
GO-2026-5381
OPENSUSE-SU-2026:21483-1

Affected Products

Prometheus