7.5

CVE-2026-42154

Prometheus: remote read endpoint allows denial of service via crafted snappy payload

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PrometheusPrometheus Version < 3.5.3
PrometheusPrometheus Version >= 3.6.0 < 3.11.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://github.com/prometheus/prometheus/releases/tag/v3.11.3
Release Notes
https://github.com/prometheus/prometheus/releases/tag/v3.5.3
Release Notes
https://github.com/prometheus/prometheus/pull/18584
Patch
Issue Tracking
https://github.com/prometheus/prometheus/pull/18585
Patch
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2466505
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42154.json
https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:25039
https://access.redhat.com/errata/RHSA-2026:25245
https://access.redhat.com/errata/RHSA-2026:29770
https://access.redhat.com/errata/RHSA-2026:30651
https://access.redhat.com/errata/RHSA-2026:34357
https://access.redhat.com/errata/RHSA-2026:34359
https://access.redhat.com/errata/RHSA-2026:34364
https://access.redhat.com/security/cve/CVE-2026-42154
https://access.redhat.com/errata/RHSA-2026:34794
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36796
https://access.redhat.com/errata/RHSA-2026:40262
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40974
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:41031
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41019
https://access.redhat.com/errata/RHSA-2026:40970
https://access.redhat.com/errata/RHSA-2026:40972
https://access.redhat.com/errata/RHSA-2026:41030
https://access.redhat.com/errata/RHSA-2026:42146
https://access.redhat.com/errata/RHSA-2026:40792
https://access.redhat.com/errata/RHSA-2026:42796
https://access.redhat.com/errata/RHSA-2026:42852
https://access.redhat.com/errata/RHSA-2026:43052
https://access.redhat.com/errata/RHSA-2026:44622
https://access.redhat.com/errata/RHSA-2026:44263
https://access.redhat.com/errata/RHSA-2026:47149
https://access.redhat.com/errata/RHSA-2026:44235
https://access.redhat.com/errata/RHSA-2026:47952
https://access.redhat.com/errata/RHSA-2026:48699
https://access.redhat.com/errata/RHSA-2026:47728
https://access.redhat.com/errata/RHSA-2026:50843
https://access.redhat.com/errata/RHSA-2026:53412
https://access.redhat.com/errata/RHSA-2026:53413
https://access.redhat.com/errata/RHSA-2026:53415
https://access.redhat.com/errata/RHSA-2026:53530
https://access.redhat.com/errata/RHSA-2026:50758
https://access.redhat.com/errata/RHSA-2026:54288
https://access.redhat.com/errata/RHSA-2026:56340