PT-2026-42350 · Cleanstart · Prometheus

Published

2026-04-14

·

Updated

2026-04-14

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Multiple security vulnerabilities affect the prometheus package. The Delete function fails to properly validate offsets when processing malformed JSON input. See references for individual vulnerability details.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CLEANSTART-2026-WA14162

Affected Products

Prometheus