CVE-2026-44903

medium
Published 2026-05-26 Β· Modified 2026-05-29
CVSS v3
β€”
CVSS v4 NEW
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
VIR risk
5.5

Description

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An attacker who can inject crafted metrics can execute JavaScript in the browser of any Prometheus user who views the metric in the heatmap chart UI. This vulnerability is fixed in 3.5.3 and 3.11.3.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2026-44903 NameCVE-2026-44903 DescriptionPrometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An…

CVE-2026-44903

NameCVE-2026-44903
DescriptionPrometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-feature=old-ui), the histogram heatmap chart view does not escape le label values when inserting them into the HTML for use as axis tick mark labels. An attacker who can inject crafted metrics can execute JavaScript in the browser of any Prometheus user who views the metric in the heatmap chart UI. This vulnerability is fixed in 3.5.3 and 3.11.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1138261

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
prometheus (PTS)bullseye2.24.1+ds-1fixed
bookworm2.42.0+ds-5fixed
trixie2.53.3+ds1-2vulnerable
forky, sid2.53.5+ds1-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
prometheussourcebullseye(not affected)
prometheussourcebookworm(not affected)
prometheussource(unstable)(unfixed)1138261

Notes

[bookworm] - prometheus <not-affected> (Vulnerable code introduced later)
[bullseye] - prometheus <not-affected> (Vulnerable code introduced later)
https://github.com/prometheus/prometheus/security/advisories/GHSA-fw8g-cg8f-9j28
Fixed by: https://github.com/prometheus/prometheus/commit/38f23b9075ced1de2b82d2dad8b2bebb1ecd5b7d
Introduced by: https://github.com/prometheus/prometheus/commit/2e205ee95c121d8d6da0d8984f0b3bc599acaa2a (v2.49.0-rc.0)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bookworm] - prometheus <not-affected> (Vulnerable code introduced later)[bullseye] - prometheus <not-affected> (Vulnerable code introduced later)https://github.com/prometheus/prometheus/security/advisories/GHSA-fw8g-cg8f-9j28Fixed by: https://github.com/prometheus/prometheus/commit/38f23b9075ced1de2b82d2dad8b2bebb1ecd5b7dIntroduced by: https://github.com/prometheus/prometheus/commit/2e205ee95c121d8d6da0d8984f0b3bc599acaa2a (v2.49.0-rc.0)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Affected β€”
forky Affected β€”
bullseye Fixed 0
bookworm Fixed 0

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/prometheus/prometheus<0.311.30.311.3
golang GOgithub.com/prometheus/prometheus< 0.311.30.311.3

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.