CVE-2026-42154
prometheus prometheus, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
- CVSS
- 7.5
- EPSS
- 0.81% 53.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.05