CVE-2026-42154

high

Description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42154.json

https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm

https://github.com/prometheus/prometheus/releases/tag/v3.5.3

https://github.com/prometheus/prometheus/releases/tag/v3.11.3

https://github.com/prometheus/prometheus/pull/18585

https://github.com/prometheus/prometheus/pull/18584

https://bugzilla.redhat.com/show_bug.cgi?id=2466505

https://access.redhat.com/security/cve/CVE-2026-42154

https://access.redhat.com/errata/RHSA-2026:47952

https://access.redhat.com/errata/RHSA-2026:47149

https://access.redhat.com/errata/RHSA-2026:44622

https://access.redhat.com/errata/RHSA-2026:44263

https://access.redhat.com/errata/RHSA-2026:44235

https://access.redhat.com/errata/RHSA-2026:43052

https://access.redhat.com/errata/RHSA-2026:42852

https://access.redhat.com/errata/RHSA-2026:42796

https://access.redhat.com/errata/RHSA-2026:42146

https://access.redhat.com/errata/RHSA-2026:41066

https://access.redhat.com/errata/RHSA-2026:41031

https://access.redhat.com/errata/RHSA-2026:41030

https://access.redhat.com/errata/RHSA-2026:41019

https://access.redhat.com/errata/RHSA-2026:40974

https://access.redhat.com/errata/RHSA-2026:40972

https://access.redhat.com/errata/RHSA-2026:40970

https://access.redhat.com/errata/RHSA-2026:40945

https://access.redhat.com/errata/RHSA-2026:40792

https://access.redhat.com/errata/RHSA-2026:40262

https://access.redhat.com/errata/RHSA-2026:40118

https://access.redhat.com/errata/RHSA-2026:36796

https://access.redhat.com/errata/RHSA-2026:36651

https://access.redhat.com/errata/RHSA-2026:34794

https://access.redhat.com/errata/RHSA-2026:34364

https://access.redhat.com/errata/RHSA-2026:34359

https://access.redhat.com/errata/RHSA-2026:34357

https://access.redhat.com/errata/RHSA-2026:30651

https://access.redhat.com/errata/RHSA-2026:29770

https://access.redhat.com/errata/RHSA-2026:25245

https://access.redhat.com/errata/RHSA-2026:25039

Details

Source: Mitre, NVD

Published: 2026-05-04

Updated: 2026-08-03

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.00021