prometheus records
11 published records for vendor prometheus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 81.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-400 Uncontrolled Resource Consumption2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-46146No exploit | Prometheus Exporter Toolkit vulnerable to basic authentication bypassprometheus · exporter toolkit · CWE-287 | High8.8 | — | 1.3% | Nov 29, 2022 |
32Monitor | CVE-2022-21698No exploit | Uncontrolled Resource Consumption in promhttpprometheus · client golang · CWE-400 | High7.5 | — | 6.0% | Feb 15, 2022 |
30Monitor | CVE-2021-29622Proof of concept | Arbitrary redirects under /new endpointprometheus · prometheus · CWE-601 | Medium6.1 | — | 19.6% | May 19, 2021 |
30Monitor | CVE-2026-42154Proof of concept | Prometheus: remote read endpoint allows denial of service via crafted snappy payloadprometheus · prometheus · CWE-400 | High7.5 | — | 0.9% | May 4, 2026 |
30Monitor | CVE-2023-26735No exploit | blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface.prometheus · blackbox exporter · CWE-918 | High7.5 | — | 0.9% | Apr 25, 2023 |
30Monitor | CVE-2026-42151No exploit | Prometheus Azure AD remote write OAuth client secret exposed via config APIprometheus · prometheus · CWE-200 | High7.5 | — | 0.4% | May 4, 2026 |
25Monitor | CVE-2019-3826No exploit | A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1.prometheus · prometheus · CWE-79 | Medium6.1 | — | 2.6% | Mar 26, 2019 |
24Monitor | CVE-2020-16248Proof of concept | Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF.prometheus · blackbox exporter · CWE-918 | Medium5.8 | — | 2.7% | Aug 9, 2020 |
21Monitor | CVE-2023-40577No exploit | Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpointprometheus · alertmanager · CWE-79 | Medium5.4 | — | 0.6% | Aug 24, 2023 |
21Monitor | CVE-2026-40179Proof of concept | Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorerprometheus · prometheus · CWE-79 | Medium5.3 | — | 0.3% | Apr 15, 2026 |
20Monitor | CVE-2026-44903No exploit | Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display of the old Prometheus web UIprometheus · prometheus · CWE-79 | Medium5.1 | — | 0.2% | May 26, 2026 |
- CVE-2022-4614635Monitor
Prometheus Exporter Toolkit vulnerable to basic authentication bypass
HighCVSS 8.8No exploitEPSS 1%prometheus · exporter toolkitNov 29, 2022
- CVE-2022-2169832Monitor
Uncontrolled Resource Consumption in promhttp
HighCVSS 7.5No exploitEPSS 6%prometheus · client golangFeb 15, 2022
- CVE-2021-2962230Monitor
Arbitrary redirects under /new endpoint
MediumCVSS 6.1Proof of conceptEPSS 20%prometheus · prometheusMay 19, 2021
- CVE-2026-4215430Monitor
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
HighCVSS 7.5Proof of conceptEPSS 1%prometheus · prometheusMay 4, 2026
- CVE-2023-2673530Monitor
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface.
HighCVSS 7.5No exploitEPSS 1%prometheus · blackbox exporterApr 25, 2023
- CVE-2026-4215130Monitor
Prometheus Azure AD remote write OAuth client secret exposed via config API
HighCVSS 7.5No exploitEPSS 0%prometheus · prometheusMay 4, 2026
- CVE-2019-382625Monitor
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1.
MediumCVSS 6.1No exploitEPSS 3%prometheus · prometheusMar 26, 2019
- CVE-2020-1624824Monitor
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF.
MediumCVSS 5.8Proof of conceptEPSS 3%prometheus · blackbox exporterAug 9, 2020
- CVE-2023-4057721Monitor
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
MediumCVSS 5.4No exploitEPSS 1%prometheus · alertmanagerAug 24, 2023
- CVE-2026-4017921Monitor
Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer
MediumCVSS 5.3Proof of conceptEPSS 0%prometheus · prometheusApr 15, 2026
- CVE-2026-4490320Monitor
Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display of the old Prometheus web UI
MediumCVSS 5.1No exploitEPSS 0%prometheus · prometheusMay 26, 2026