← Vulnerability feed

Vulnerability record · CVE-2021-29622 · published 19 May 2021

CVE-2021-29622: Prometheus open redirect vulnerability

Prometheus · Prometheus

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

6.1 CVSS 3.1 Medium EPSS 20% · top 2.7% CWE-601 · Open redirect
6.1CVSS 3.1 base score, v2 5.8
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable access to /new via a reverse proxy in front of Prometheus.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-42151Prometheus information exposure vulnerabilityPrometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD …EPSS 0.41%7.5CVE-2026-42154Prometheus uncontrolled resource consumption vulnerabilityPrometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) …EPSS 0.89%6.1CVE-2019-3826Prometheus cross-site scripting vulnerabilityA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an au…EPSS 2.6%5.3CVE-2026-40179Prometheus cross-site scripting vulnerabilityPrometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site s…EPSS 0.31%5.1CVE-2026-44903Prometheus cross-site scripting vulnerabilityPrometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we…EPSS 0.24%4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed6.1CVE-2021-38000Google Chrome Android Intents input validation open redirectChrome on Android before 95.0.4638.69 fails to properly validate untrusted input passed through Intents, allowing a crafted HTML page to redirect the…KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2021-29622), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.