OVERVIEW CVE-2026-40179 is a stored cross-site scripting (XSS) vulnerability affecting Prometheus versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1. The vulnerability exists in multiple web UI components where metric names and label values are rendered into innerHTML without proper sanitization. Specifically, chart tooltips in the Graph page and fuzzy search results fail to escape user-supplied input, allowing malicious metric names and labels to contain unescaped HTML and JavaScript code. SEVERITY The vulnerability carries a CVSS score of 6.1 (Medium) with a network attack vector, low complexity, and no privilege requirements, though user interaction is necessary. The attack surface requires an attacker to inject malicious metrics via compromised scrape targets, remote write endpoints, or OTLP receivers. Once a user views the poisoned metric in the Graph UI, arbitrary JavaScript executes in their browser context, potentially enabling configuration exfiltration, sensitive data deletion, or Prometheus service disruption depending on enabled administrative flags. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. The EPSS score of 0.00011 indicates very low real-world exploitation probability relative to other CVEs. Community attention remains minimal as evidenced by the vulnerability's inactive status on threat intelligence lists. Patches are available in versions 3.5.2 and 3.11.2, and administrators should prioritize updating or implementing recommended mitigations such as restricting remote write and OTLP receivers from untrusted sources and ensuring all scrape targets are from trusted origins.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.5.2CPE matchmatch criteria | cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.11.2CPE matchmatch criteria | cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.