Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses that Prometheus exposes Azure OAuth client secrets in plaintext via its /-/config API, provides a patch (v3.5.3 / v3.11.3), and urges immediate upgrade and access review.
Upwind Security MDR[verified]@UpwindMDRPatch
The alert announces two high‑severity CVEs in Prometheus and urges immediate patching and API restriction.
WindowsForum[verified]@windowsforumDisclosure
The post announces CVE‑2026‑42151 as a flaw that leaks secrets through plaintext OAuth configuration APIs on Windows systems running Linux containers, without mentioning PoC, exploit, or remediation details.
DFIR Lab[verified]@DFIR_LabPatch
Prometheus versions before 3.5.3 and 3.11.3 expose Azure AD OAuth client_secrets in plaintext via the /-/config API, necessitating immediate patching.
CVE@CVEnewPatch
The excerpt indicates a CVE affecting Prometheus with a fixed version noted, but lacks details on exploitation or PoC and does not mention any active attacks.
DailyCVE@dailycveDisclosure
The text announces CVE-2026-42151 as a high‑severity information exposure issue in Prometheus, without providing technical details, patches, or exploitation evidence.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
New CVE disclosed that exposes Azure AD OAuth client secrets in older Prometheus versions, with technical details provided but no PoC, exploit, or patch information.
Infoflowcloud@infoflowcloudDisclosure
The message announces CVE-2026-42151 affecting Prometheus versions 3.5.3 and 3.11.3, detailing the vulnerable field context but providing no exploitation or mitigation information.