CVE-2019-3826: Prometheus

Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

Affected products

  • Prometheus Prometheus: before 2.7.1 (fixed in 2.7.1)
  • Red Hat Openshift Container Platform: version 3.11 only

Published 2019-03-26. Last modified 2026-06-17.