PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40179 prometheus CVE debrief

CVE-2026-40179 is a stored cross-site scripting (XSS) vulnerability in the Prometheus web UI. When a user hovers over a chart tooltip on the Graph page, opens the Metric Explorer, or views a heatmap chart, crafted metric names or label values can be injected into `innerHTML` without escaping, causing arbitrary script execution in the user's browser. This issue affects multiple versions of the Prometheus product, with fixes available in versions 3.5.2, 3.11.2, and 0.311.2-0.20260410083055-07c6232d159b.

Vendor
prometheus
Product
github.com/prometheus/prometheus
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-13
Original CVE updated
2026-10-06
Advisory published
2026-04-13
Advisory updated
2026-10-06

Who should care

Defenders responsible for Prometheus deployments, especially those using older versions or the Old React UI, should assess exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-40179 is a stored XSS vulnerability in Prometheus web UI that allows script injection via crafted metric names or label values, impacting users of older versions or the Old React UI. Defenders should verify exposure, prioritize remediation, and consider compensating controls.

  • Script execution in user's browser via crafted metric names or label values
  • Potential for arbitrary code execution in the context of the user's session
  • Possible data theft or unauthorized actions within the Prometheus web UI
  • Need for verification of exposure and remediation priority in Prometheus deployments

Technical summary

The vulnerability allows stored cross-site scripting (XSS) via crafted metric names in the Prometheus web UI. Specifically, when a user hovers over a chart tooltip on the Graph page, opens the Metric Explorer, or views a heatmap chart, metric names or label values containing HTML/JavaScript can be injected into `innerHTML` without escaping, causing arbitrary script execution in the user's browser. This issue affects multiple versions of the Prometheus product, with fixes available in versions 3.5.2, 3.11.2, and 0.311.2-0.20260410083055-07c6232d159b.

Defensive priority

Defenders should prioritize verifying exposure in their Prometheus deployments, especially if using older versions or the Old React UI, and assess the feasibility of upgrading to patched versions or applying compensating controls.

Recommended defensive actions

  • Verify Prometheus version and assess exposure
  • Upgrade to patched versions (3.5.2, 3.11.2, or 0.311.2-0.20260410083055-07c6232d159b) if applicable
  • Implement compensating controls, such as input validation and content security policy
  • Monitor for suspicious activity and anomalous script execution
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed through multiple sources, including the official CVE Program record, NVD vulnerability detail, and source item from osv_dev. However, details on exploitation, victims, or business impact are limited or not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40179 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40179

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40179 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40179

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.