Stored cross-site scripting in prometheus - CVE-2026-40179
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the Prometheus web UI tooltip and metrics explorer components when rendering crafted metric names or label values. A remote user can inject crafted metrics through a compromised scrape target, remote write, or the OTLP receiver endpoint to execute arbitrary script in the victim's browser.
User interaction is required to view the affected metric in the Graph UI, such as hovering over a chart tooltip, opening the Metric Explorer, or hovering over a heatmap cell.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
golang-github-prometheus-node_exporter
golang-github-prometheus-node_exporter-debuginfo
golang-github-prometheus-prometheus-debuginfo
golang-github-prometheus-prometheus
release-notes-susemanager-proxy
release-notes-susemanager
How to mitigate CVE-2026-40179
golang-github-prometheus-node_exporter - update to 1.10.2-150100.3.42.1
golang-github-prometheus-node_exporter-debuginfo - update to 1.10.2-150100.3.42.1
golang-github-prometheus-prometheus-debuginfo - update to 3.5.3-150100.4.34.1
golang-github-prometheus-prometheus - update to 3.5.3-150100.4.34.1
release-notes-susemanager-proxy - update to 4.3.18-150400.3.110.2
release-notes-susemanager - update to 4.3.18-150400.3.154.2