VulnSea

prometheus has 5 CVEs on record between 2022 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: prometheus (2), blackbox_exporter (1), github.com/prometheus/exporter-toolkit (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 2

Products

  • prometheus 2
  • blackbox_exporter 1
  • github.com/prometheus/exporter-toolkit 1
  • github.com/prometheus/prometheus 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

prometheus vulnerabilities

CVEs affecting prometheus, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-40179NonePoC
2mo ago

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

Prometheus has Stored XSS via metric names and label values in Prometheus web UI in github.com/prometheus/prometheus

Twilightprometheus · github.com/prometheus/prometheusEPSS 0.26%via OSV
CVE-2026-42151High· 7.5
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…

Twilightprometheus · prometheusEPSS 0.35%via NVD
CVE-2026-42154High· 7.5PoC
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before…

Midnightprometheus · prometheusEPSS 0.81%via NVD
CVE-2023-26735High· 7.5
3y ago

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface

blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as well as download resources. NOTE: this is disputed by third…

Twilightprometheus · blackbox_exporterEPSS 0.89%via NVD
CVE-2022-46146Medium· 6.2
3y ago

Prometheus Exporter-Toolkit is vulnerable to authentication bypass

Prometheus Exporter-Toolkit is vulnerable to authentication bypass

Sunlitprometheus · github.com/prometheus/exporter-toolkitEPSS 1.2%via OSV
prometheus vulnerabilities (CVEs) · VulnSea