GO-2026-5381
Dashboard / Vulnerabilities / GO-2026-5381
Summary: Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display in github.com/prometheus/prometheus
Details: Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display in github.com/prometheus/prometheus
References: https://github.com/prometheus/prometheus/security/advisories/GHSA-fw8g-cg8f-9j28, https://nvd.nist.gov/vuln/detail/CVE-2026-44903, https://github.com/prometheus/prometheus/commit/38f23b9075ced1de2b82d2dad8b2bebb1ecd5b7d
Affected packages
Package
Name: github.com/prometheus/prometheus
Purl: pkg:golang/github.com/prometheus/prometheus
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.311.3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
