Known vulnerabilities in prometheus-blackbox_exporter
Vendor:
SUSE
Software:
prometheus-blackbox_exporter
Software CPE:
cpe:2.3:o:suse:prometheus-blackbox_exporter:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
77
Public exploits:
5
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.26.0-160002.2.1
0.26.0-150002.3.11.1
0.26.0-150002.3.6.1
0.26.0-160002.1.1
0.26.0-159000.2.2.1
0.26.0-150000.1.30.2
0.26.0-150002.3.3.1
0.26.0-120002.3.3.1
0.26.0-150000.1.27.1
0.26.0-1.27.1
0.24.0-3.6.3
0.24.0-159000.3.6.1
0.24.0-1.23.2
0.24.0-150000.1.23.3
0.24.0-1.20.3
0.24.0-150000.1.20.2
0.19.0-150000.1.17.2
0.19.0-1.17.1
0.19.0-150000.1.11.1
0.19.0-1.8.2
0.19.0-3.3.2
0.19.0-3.3.1
Vulnerabilities (77)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128147 - Resource exhaustion CVE-2026-31958 |
CWE-400 | Medium | 0.26.0-160002.1.1 | 27.04.2026 |
SB20260427102 SB20260427109 SB20260427110 and 40 more |
||
| #VU124876 - Inefficient Regular Expression Complexity CVE-2026-25547 |
CWE-1333 | Low | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 06.04.2026 |
SB2026040628 SB2026040631 SB2026040632 and 13 more |
||
| #VU123311 - Improper Control of Generation of Code ('Code Injection') CVE-2026-1615 |
CWE-94 | High | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 27.02.2026 |
SB2026022707 SB2026022708 SB2026032720 and 4 more |
||
| #VU123310 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-61140 |
CWE-1321 | High | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 27.02.2026 |
SB2026022706 SB2026022708 SB2026030405 and 3 more |
||
| #VU123174 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-27606 |
CWE-22 | High | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 24.02.2026 |
SB2026022445 SB2026040631 SB2026040632 and 4 more |
||
| #VU122756 - Improper Access Control CVE-2026-21722 |
CWE-284 | Low | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 12.02.2026 |
SB2026021238 SB20260325198 SB2026040631 and 1 more |
||
| #VU122160 - Resource Management Errors CVE-2026-21720 |
CWE-399 | Medium | 0.26.0-150000.1.30.2 | 30.01.2026 |
SB2026013061 SB20260325198 SB2026040631 |
||
| #VU122159 - Improper Privilege Management CVE-2026-21721 |
CWE-269 | Low | 0.26.0-150000.1.30.2 | 30.01.2026 |
SB2026013061 SB2026022335 SB2026030249 and 4 more |
||
| #VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-13465 |
CWE-1321 | Medium | 0.26.0-150000.1.30.2 | 22.01.2026 |
SB2026012209 SB2026012701 SB2026012744 and 71 more |
||
| #VU120232 - Uncontrolled Recursion CVE-2025-68156 |
CWE-674 | Medium | 0.26.0-120002.3.3.1, 0.26.0-150000.1.30.2, 0.26.0-150002.3.3.1 | 22.12.2025 |
SB2025122249 SB2025122250 SB2025122251 and 12 more |
||
| #VU120229 - Improper Authentication CVE-2025-62349 |
CWE-287 | Low | 0.26.0-159000.2.2.1 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU120228 - Improper Control of Generation of Code ('Code Injection') CVE-2025-62348 |
CWE-94 | Medium | 0.26.0-159000.2.2.1 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU119885 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2025-67724 |
CWE-644 | Low | 0.26.0-159000.2.2.1 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 35 more |
||
| #VU119884 - Excessive Iteration CVE-2025-67725 |
CWE-834 | Low | 0.26.0-159000.2.2.1 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 41 more |
||
| #VU119883 - Excessive Iteration CVE-2025-67726 |
CWE-834 | Medium | 0.26.0-159000.2.2.1 | 12.12.2025 |
SB2025121205 SB2025123045 SB2026010587 and 41 more |
||
| #VU119131 - Interpretation Conflict CVE-2025-12816 |
CWE-436 | Medium | 0.26.0-120002.3.3.1, 0.26.0-150000.1.30.2, 0.26.0-150002.3.3.1 | 04.12.2025 |
SB2025120419 SB2025122219 SB20260116128 and 19 more |
||
| #VU113081 - Exposure of sensitive information to an unauthorized actor CVE-2025-3415 |
CWE-200 | Medium | 0.26.0-150000.1.30.2, 0.26.0-159000.2.2.1 | 21.07.2025 |
SB2025072113 SB2025112453 SB2025112454 and 3 more |
||
| #VU72130 - Exposure of sensitive information to an unauthorized actor CVE-2022-31130 |
CWE-200 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 11 more |
||
| #VU69485 - Exposure of sensitive information to an unauthorized actor CVE-2022-39307 |
CWE-200 | Medium | 0.24.0-3.6.3, 0.24.0-159000.3.6.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU68897 - Resource exhaustion CVE-2022-32149 |
CWE-400 | Medium | 0.24.0-1.23.2, 0.24.0-3.6.3, 0.24.0-150000.1.23.3, 0.24.0-159000.3.6.1 | 01.11.2022 |
SB2022110139 SB2022110140 SB2022110142 and 68 more |
Showing elements 1 - 20 out of 77