---
id: CVE-2026-40179
aliases:
  - GO-2026-5662
  - BIT-prometheus-2026-40179
  - GHSA-vffh-x6r8-xx99
title: >-
  Prometheus has Stored XSS via metric names and label values in Prometheus web
  UI in github.com/prometheus/prometheus
summary: >-
  Prometheus has Stored XSS via metric names and label values in Prometheus web
  UI in github.com/prometheus/prometheus
severity: none
vendor: prometheus
product: github.com/prometheus/prometheus
ecosystem: go
affected:
  - github.com/prometheus/prometheus < 0.311.2-0.20260410083055-07c6232d159b
patched:
  - github.com/prometheus/prometheus 0.311.2-0.20260410083055-07c6232d159b
published: '2026-06-25'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-5662'
references:
  - url: >-
      https://github.com/prometheus/prometheus/security/advisories/GHSA-vffh-x6r8-xx99
  - url: >-
      https://github.com/prometheus/prometheus/commit/07c6232d159bfb474a077788be184d87adcfac3c
  - url: 'https://github.com/prometheus/prometheus/pull/18506'
tags:
  - osv
  - go
  - exploit-available
epss: 0.00259
epssPercentile: 0.17936
ingestedAt: '2026-07-09T18:56:37.238Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/bsdrip/CVE-2026-40179-PoC'
  checkedAt: '2026-09-24T07:53:03.091Z'
exploitAvailable: true
---

## Overview

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

## Affected packages

- `github.com/prometheus/prometheus < 0.311.2-0.20260410083055-07c6232d159b`

## Remediation

Upgrade to a patched release:

- `github.com/prometheus/prometheus 0.311.2-0.20260410083055-07c6232d159b`
