prometheus has 5 CVEs on record between 2022 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: prometheus (2), blackbox_exporter (1), github.com/prometheus/exporter-toolkit (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Products
- prometheus 2
- blackbox_exporter 1
- github.com/prometheus/exporter-toolkit 1
- github.com/prometheus/prometheus 1
Worst active — by depth score
CVE-2026-42154High· 7.5Prometheus is an open-source monitoring system and time series database53CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database41CVE-2023-26735High· 7.5blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface41CVE-2022-46146Medium· 6.2Prometheus Exporter-Toolkit is vulnerable to authentication bypass34CVE-2026-40179NonePrometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus15
prometheus vulnerabilities
CVEs affecting prometheus, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-40179NonePoCPrometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…
CVE-2026-42154High· 7.5PoCPrometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…
CVE-2023-26735High· 7.5blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third…
CVE-2022-46146Medium· 6.2Prometheus Exporter-Toolkit is vulnerable to authentication bypass
Prometheus Exporter-Toolkit is vulnerable to authentication bypass