CVE-2026-40179None▾ TwilightPoC availablePrometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 2.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.3%
1 GitHub repo
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
github.com/prometheus/prometheus < 0.311.2-0.20260410083055-07c6232d159bUpgrade to a patched release:
github.com/prometheus/prometheus 0.311.2-0.20260410083055-07c6232d159bField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-46146Medium· 6.2Prometheus Exporter-Toolkit is vulnerable to authentication bypass
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
CVE-2026-42154High· 7.5Prometheus is an open-source monitoring system and time series database
CVE-2023-26735High· 7.5blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface