← Vulnerability feed

Vulnerability record · CVE-2026-42154 · published 4 May 2026

CVE-2026-42154: Prometheus uncontrolled resource consumption vulnerability

Prometheus · Prometheus

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

7.5 CVSS 3.1 High EPSS 0.89% · top 42.1% CWE-400 · Uncontrolled resource consumptionCWE-789 · CWE-789
7.5CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
10 Sep 2026Last modified by NVD

Description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/prometheus/prometheus/pull/18584 Issue TrackingPatch
https://github.com/prometheus/prometheus/pull/18585 Issue TrackingPatch
https://github.com/prometheus/prometheus/releases/tag/v3.11.3 Release Notes
https://github.com/prometheus/prometheus/releases/tag/v3.5.3 Release Notes
https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:25039
https://access.redhat.com/errata/RHSA-2026:25245
https://access.redhat.com/errata/RHSA-2026:29770
https://access.redhat.com/errata/RHSA-2026:30651
https://access.redhat.com/errata/RHSA-2026:34357
https://access.redhat.com/errata/RHSA-2026:34359
https://access.redhat.com/errata/RHSA-2026:34364
https://access.redhat.com/errata/RHSA-2026:34794
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36796
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40262
https://access.redhat.com/errata/RHSA-2026:40792
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:40970
https://access.redhat.com/errata/RHSA-2026:40972
https://access.redhat.com/errata/RHSA-2026:40974
https://access.redhat.com/errata/RHSA-2026:41019
https://access.redhat.com/errata/RHSA-2026:41030
https://access.redhat.com/errata/RHSA-2026:41031
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:42146
https://access.redhat.com/errata/RHSA-2026:42796
https://access.redhat.com/errata/RHSA-2026:42852
https://access.redhat.com/errata/RHSA-2026:43052
https://access.redhat.com/errata/RHSA-2026:44235
https://access.redhat.com/errata/RHSA-2026:44263
https://access.redhat.com/errata/RHSA-2026:44622
https://access.redhat.com/errata/RHSA-2026:47149
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:47952
https://access.redhat.com/errata/RHSA-2026:48699
https://access.redhat.com/errata/RHSA-2026:50758
https://access.redhat.com/errata/RHSA-2026:50843
https://access.redhat.com/errata/RHSA-2026:53412

Track CVE-2026-42154 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-42151Prometheus information exposure vulnerabilityPrometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD …EPSS 0.41%6.1CVE-2021-29622Prometheus open redirect vulnerabilityPrometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seam…EPSS 20%6.1CVE-2019-3826Prometheus cross-site scripting vulnerabilityA stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an au…EPSS 2.6%5.3CVE-2026-40179Prometheus cross-site scripting vulnerabilityPrometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site s…EPSS 0.31%5.1CVE-2026-44903Prometheus cross-site scripting vulnerabilityPrometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we…EPSS 0.24%7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2026-45498Microsoft Defender antimalware platform uncontrolled resource consumption DoSCVE-2026-45498 is a denial of service flaw in the Microsoft Defender antimalware platform, classified as uncontrolled resource consumption (CWE-400).…KEVEPSS 1.3%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-42154), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.