CVE-2026-42154Disclosure(prometheus / prometheus)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch prometheus prometheus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-789CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • prometheus

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-04); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
prometheus

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 2Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 2Technical Details · 2026-05-25: 105-0405-0505-25
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-052
Disclosure1General1
2026-05-251
Patch1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Prometheus Security Alert 🚨 Two high-severity vulnerabilities just dropped in Prometheus: • CVE-2026-42154 – Remote read endpoint DoS via crafted snappy payload • CVE-2026-42151 – Azure AD OAuth client secret exposure via config API Both impact http://github.com/prometheus/prometheus (Go). 👉 Potential impact: service disruption + credential leakage Patch ASAP and restrict access to remote read/config APIs.

    Post summary

    Two high‑severity Prometheus vulnerabilities have been disclosed – a DoS via a crafted snappy payload and an Azure AD OAuth client secret leak – with patching and API restrictions recommended.

    00020137
    237 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate… https://www.cve.org/CVERecord?id=CVE-2026-42154

    Post summary

    The post announces CVE‑2026‑42154, noting a validation issue in Prometheus's remote read endpoint prior to versions 3.5.3 and 3.11.3, without providing PoC, exploit, or patch details.

    00010164
    57.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-42154 (CVSS 7.5) - Prometheus memory exhaustion flaw allows unauthenticated DoS via snappy-compressed payloads. Affects versions <3.5.3 & <3.11.3. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/2Dtm1MDQVQ

    Post summary

    The tweet highlights a high‑severity memory exhaustion flaw in Prometheus that allows unauthenticated DoS via snappy‑compressed payloads, and urges users to apply the available patch immediately.

    0000049
    30 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42154 Denial of Service via Unvalidated Snappy Decompression in Prometheus Remote Read Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42154

    Post summary

    The text links to a vulnerability listing for CVE‑2026‑42154, describing a DoS issue in Prometheus, but offers no evidence of exploitation, mitigation, or additional detailed analysis.

    0000049
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate… https://www.cve.org/CVERecord?id=CVE-2026-42154 ----- Traducción: CVE-2026-42154 Pro… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-42154 for Prometheus, noting that prior versions’ remote read endpoint is missing validation, but offers no PoC, exploitation code, or patch details.

    0000033
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprometheusprometheus---

Explore more