CVE-2026-42154

Source
https://cve.org/CVERecord?id=CVE-2026-42154
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42154.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-42154
Aliases
Downstream
Related
Published
2026-05-04T18:13:12.340Z
Modified
2026-06-25T19:56:12.114245941Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
Details

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42154.json",
    "cwe_ids": [
        "CWE-400",
        "CWE-789"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/prometheus/prometheus

Affected ranges

Type
GIT
Repo
https://github.com/prometheus/prometheus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.5.3"
        },
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "3.11.3"
        }
    ]
}

Affected versions

0.*
0.1.0
0.10.0
0.11.1
0.12.0
0.13.0
0.13.0rc2
0.13.1
0.13.2
0.14.0
0.14.0rc1
0.14.0rc2
0.14.0rc3
0.15.0
0.15.0rc1
0.15.0rc2
0.15.0rc3
0.15.1
0.16.0
0.16.0rc1
0.16.0rc2
0.18.0
0.18.0rc1
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.0rc1
0.9.0rc2
0.9.0rc3
0.9.0rc4
0.9.0rc5
Other
checkout
dev
discovery-handle-discoverer-updates
v0.*
v0.300.0-beta.1
v0.305.0
v0.305.1
v0.305.2
v0.311.0
v0.311.1
v0.311.2
v0.43.0-rc.0
v1.*
v1.0.0-rc.0
v1.1.0
v1.3.0-beta.0
v1.4.0
v1.4.1
v2.*
v2.0.0-alpha.0
v2.0.0-alpha.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-beta.0
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-rc.0
v2.0.0-rc.1
v2.0.0-rc.2
v2.0.0-rc.3
v2.1.0
v2.10.0-rc.0
v2.11.0-rc.0
v2.12.0-rc.0
v2.13.0-rc.0
v2.2.0
v2.2.0-rc.0
v2.2.0-rc.1
v2.22.0-rc.0
v2.32.0-beta.0
v2.34.0-rc.0
v2.4.0
v2.4.0-rc.0
v2.43.0-rc.0
v2.5.0-rc.0
v2.6.0
v2.6.0-rc.0
v2.6.0-rc.1
v2.7.0
v2.7.0-rc.0
v2.7.0-rc.1
v2.7.0-rc.2
v2.8.0
v2.8.0-rc.0
v2.9.0
v2.9.0-rc.0
v3.*
v3.0.0-beta.1
v3.11.0
v3.11.1
v3.11.2
v3.5.0
v3.5.0-rc.0
v3.5.0-rc.1
v3.5.1
v3.5.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42154.json"