Skip to content

prometheus

v3.5.4 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo Monitoring & Metrics
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

alerting graphing prometheus monitoring time-series

Affected surfaces

auth deps

Summary

AI summary

Fixes secrets exposure via /-/config endpoint and bumps dependencies to address multiple CVEs.

Full changelog

This release fixes multiple security issues.

  • [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via /-/config endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18650
  • [SECURITY] Dependencies: Bump golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0 to fix reported CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985). #18934
  • [SECURITY] UI: Bump mantine-ui dependencies (react-router-dom, vitest, vite, postcss) to their patched versions to resolve security advisories. #18935
  • [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18792

Security Fixes

  • GHSA-39j6-789q-qxvh – secrets exposed in plaintext via /-/config endpoint
  • dep: GO-2026-5026, GO-2026-4918, GO-2026-4985 fixed by bumping golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0
  • dep: Security advisories resolved by bumping mantine-ui dependencies (react-router-dom, vitest, vite, postcss)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track prometheus

Get notified when new releases ship.

Sign up free

About prometheus

The Prometheus monitoring system and time series database.

All releases →

Related context

Beta — feedback welcome: [email protected]