PatchSiren cyber security CVE debrief
CVE-2026-40179 prometheus CVE debrief
CVE-2026-40179 is a stored cross-site scripting (XSS) vulnerability in the Prometheus web UI. When a user hovers over a chart tooltip on the Graph page, opens the Metric Explorer, or views a heatmap chart, crafted metric names or label values can be injected into `innerHTML` without escaping, causing arbitrary script execution in the user's browser. This issue affects multiple versions of the Prometheus product, with fixes available in versions 3.5.2, 3.11.2, and 0.311.2-0.20260410083055-07c6232d159b.
- Vendor
- prometheus
- Product
- github.com/prometheus/prometheus
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-13
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-04-13
- Advisory updated
- 2026-10-06
Who should care
Defenders responsible for Prometheus deployments, especially those using older versions or the Old React UI, should assess exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-40179 is a stored XSS vulnerability in Prometheus web UI that allows script injection via crafted metric names or label values, impacting users of older versions or the Old React UI. Defenders should verify exposure, prioritize remediation, and consider compensating controls.
- Script execution in user's browser via crafted metric names or label values
- Potential for arbitrary code execution in the context of the user's session
- Possible data theft or unauthorized actions within the Prometheus web UI
- Need for verification of exposure and remediation priority in Prometheus deployments
Technical summary
The vulnerability allows stored cross-site scripting (XSS) via crafted metric names in the Prometheus web UI. Specifically, when a user hovers over a chart tooltip on the Graph page, opens the Metric Explorer, or views a heatmap chart, metric names or label values containing HTML/JavaScript can be injected into `innerHTML` without escaping, causing arbitrary script execution in the user's browser. This issue affects multiple versions of the Prometheus product, with fixes available in versions 3.5.2, 3.11.2, and 0.311.2-0.20260410083055-07c6232d159b.
Defensive priority
Defenders should prioritize verifying exposure in their Prometheus deployments, especially if using older versions or the Old React UI, and assess the feasibility of upgrading to patched versions or applying compensating controls.
Recommended defensive actions
- Verify Prometheus version and assess exposure
- Upgrade to patched versions (3.5.2, 3.11.2, or 0.311.2-0.20260410083055-07c6232d159b) if applicable
- Implement compensating controls, such as input validation and content security policy
- Monitor for suspicious activity and anomalous script execution
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is confirmed through multiple sources, including the official CVE Program record, NVD vulnerability detail, and source item from osv_dev. However, details on exploitation, victims, or business impact are limited or not provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40179 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40179
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40179 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40179
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and me
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-vffh-x6r8-xx99.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/prometheus/prometheus/security/advisories/GHSA-vffh-x6r8-xx99
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/prometheus/prometheus/pull/18506
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/prometheus/prometheus/commit/07c6232d159bfb474a077788be184d87adcfac3c
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/prometheus/prometheus
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.