CVE-2019-3826: Prometheus
Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
Affected products
- Prometheus Prometheus: before 2.7.1 (fixed in 2.7.1)
- Red Hat Openshift Container Platform: version 3.11 only
Published 2019-03-26. Last modified 2026-06-17.