Prometheus is a widely adopted open-source monitoring and alerting platform whose vulnerability footprint spans its core server, exporters, client libraries, and supporting tools—components deeply embedded across cloud-native and containerized infrastructure. The recurring exposure centers on web-facing input handling and network interaction patterns, with vulnerabilities clustering around cross-site scripting, server-side request forgery, and resource-consumption flaws that are characteristic of HTTP-based collection and metrics-serving roles, and the vendor's disclosures have frequently acquired public exploit code. Defenders should prioritize network segmentation and access controls around Prometheus instances and exporters, since their role in the observability stack makes them attractive pivoting points; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prometheus over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29622MEDIUM Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's pref | May 19, 2021 | 6.1 | 42 | NO | YES |
CVE-2026-42151HIGH Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuratio | May 4, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-42154HIGH Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared | May 4, 2026 | 7.5 | 35 | NO | NO |
CVE-2020-16248MEDIUM Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality | Aug 9, 2020 | 5.8 | 32 | NO | YES |
CVE-2022-46146HIGH Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passw | Nov 29, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-21698HIGH client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In clien | Feb 15, 2022 | 7.5 | 28 | NO | NO |
CVE-2026-44903MEDIUM Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-l | May 26, 2026 | 6.1 | 27 | NO | NO |
CVE-2023-26735HIGH blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect intranet ports and services, as we | Apr 26, 2023 | 7.5 | 26 | NO | NO |
CVE-2026-40179MEDIUM Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in mul | Apr 15, 2026 | 6.1 | 23 | NO | NO |
CVE-2023-40577MEDIUM Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could | Aug 25, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prometheus.
Media articles that mention a CVE ID that affects a product developed by Prometheus — matched by CVE ID, not by vendor name.