---
cve: "CVE-2026-42154"
severity: "HIGH"
cvss: 7.5
epss: "81%"
vendor: "prometheus"
kev: false
exploited: false
published: "2026-05-04 19:16:04"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T21:35:23+02:00"
---

# CVE-2026-42154

> 7.5 HIGH · 🧪 PoC

## Beschreibung

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- dcd3d551ced8b8dc14e0217f8cb14e547109cd5f (Commit)
- eb173f5256d4022afba1e9bc3d19740a76859fae (Commit)

## Referenzen

- <https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm>
- <https://github.com/prometheus/prometheus/pull/18584>
- <https://github.com/prometheus/prometheus/pull/18585>
- <https://github.com/prometheus/prometheus/releases/tag/v3.11.3>
- <https://github.com/prometheus/prometheus/releases/tag/v3.5.3>
- <https://access.redhat.com/errata/RHSA-2026:25039>
- <https://access.redhat.com/errata/RHSA-2026:25245>
- <https://access.redhat.com/errata/RHSA-2026:29770>
- <https://access.redhat.com/errata/RHSA-2026:30651>
- <https://access.redhat.com/errata/RHSA-2026:34357>
- <https://access.redhat.com/errata/RHSA-2026:34359>
- <https://access.redhat.com/errata/RHSA-2026:34364>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-42154) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
