
🚨 Prometheus Security Alert 🚨 Two high-severity vulnerabilities just dropped in Prometheus: • CVE-2026-42154 – Remote read endpoint DoS via crafted snappy payload • CVE-2026-42151 – Azure AD OAuth client secret exposure via config API Both impact http://github.com/prometheus/prometheus (Go). 👉 Potential impact: service disruption + credential leakage Patch ASAP and restrict access to remote read/config APIs.
Post summary
Two high‑severity Prometheus vulnerabilities have been disclosed – a DoS via a crafted snappy payload and an Azure AD OAuth client secret leak – with patching and API restrictions recommended.




