Your message dated Fri, 24 Jul 2026 01:25:24 +0000
with message-id <[email protected]>
and subject line Bug#1135999: fixed in prometheus 3.5.3+ds1-1
has caused the Debian Bug report #1135999,
regarding prometheus: CVE-2026-42151 CVE-2026-42154
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1135999: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1135999
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: prometheus
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for prometheus.

CVE-2026-42151[0]:
| Prometheus is an open-source monitoring system and time series
| database. Prior to versions 3.5.3 and 3.11.3, the client_secret
| field in the Azure AD remote write OAuth configuration
| (storage/remote/azuread) was typed as string instead of Secret.
| Prometheus redacts fields of type Secret when serving the
| configuration via the /-/config HTTP API endpoint. Because the field
| was a plain string, the Azure OAuth client secret was exposed in
| plaintext to any user or process with access to that endpoint. This
| issue has been patched in versions 3.5.3 and 3.11.3.

https://github.com/prometheus/prometheus/security/advisories/GHSA-wg65-39gg-5wfj
https://github.com/prometheus/prometheus/pull/18587
https://github.com/prometheus/prometheus/pull/18590


CVE-2026-42154[1]:
| Prometheus is an open-source monitoring system and time series
| database. Prior to versions 3.5.3 and 3.11.3, the remote read
| endpoint (/api/v1/read) does not validate the declared decoded
| length in a snappy-compressed request body before allocating memory.
| An unauthenticated attacker can send a small payload that causes a
| huge heap allocation per request. Under concurrent load this can
| exhaust available memory and crash the Prometheus process. This
| issue has been patched in versions 3.5.3 and 3.11.3.

https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm
https://github.com/prometheus/prometheus/pull/18584
https://github.com/prometheus/prometheus/pull/18585


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-42151
    https://www.cve.org/CVERecord?id=CVE-2026-42151
[1] https://security-tracker.debian.org/tracker/CVE-2026-42154
    https://www.cve.org/CVERecord?id=CVE-2026-42154

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: prometheus
Source-Version: 3.5.3+ds1-1
Done: Reinhard Tartler <[email protected]>

We believe that the bug you reported is fixed in the latest version of
prometheus, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reinhard Tartler <[email protected]> (supplier of updated prometheus package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 19 Jul 2026 10:17:49 -0300
Source: prometheus
Architecture: source
Version: 3.5.3+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Reinhard Tartler <[email protected]>
Closes: 1135260 1135999 1138247
Changes:
 prometheus (3.5.3+ds1-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release 3.5.3. (Closes: #1138247)
     - Fixes CVE-2026-42151 and CVE-2026-42154. (Closes: #1135999)
     - Fixes flaky tests. (Closes: #1135260)
   * Refresh patches.
   * Drop web UI due to missing dependencies in Debian (rust-rolldown).
   * Drop obsolete UI dependencies (fonts, libjs) from debian/control.
   * Drop legacy UTF-8 label validation patches to fix test panics and
     restore test coverage.
   * Add comprehensive autopkgtest for Prometheus systemd service.
Checksums-Sha1:
 204071420470747a055b2f4778510238a1164a0b 4873 prometheus_3.5.3+ds1-1.dsc
 3adc4411c506c14c50ca52e4579571b37d70f623 2005108 
prometheus_3.5.3+ds1.orig.tar.xz
 86f6c0206454134cfe3686debd7dcee8b600bfc7 78980 
prometheus_3.5.3+ds1-1.debian.tar.xz
Checksums-Sha256:
 188182e4314ed6da141e40da6b72697c0fa3099aeac40cb4b9a4c147203d3011 4873 
prometheus_3.5.3+ds1-1.dsc
 271a91b47e6ff9e507bf94e8c9eb76005ff24afd07a713bd1345a4b98e3add1c 2005108 
prometheus_3.5.3+ds1.orig.tar.xz
 def2b7a7f02c22ee669497ef9b9e7de91e33e4497144f1332f13e8ba14b0d721 78980 
prometheus_3.5.3+ds1-1.debian.tar.xz
Files:
 863f23f0679947b3b4f2144d3cbabc36 4873 golang optional 
prometheus_3.5.3+ds1-1.dsc
 5375a4d3c60f768f92a6a47535d9d380 2005108 golang optional 
prometheus_3.5.3+ds1.orig.tar.xz
 2fe2c37ac7f75edcc2b7492e8d30c7bb 78980 golang optional 
prometheus_3.5.3+ds1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmpirbMUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJstYPRAAjUutk9meph4Jz/emDA/Z3O0aqwk3
Ox65CUBYQ+mZPpUiM392Y1Q/CO3A6bTwexsGgQjvh9Mb7OS3BKHWqtvSyf6CIlUt
3OS1Z5dpSRWTxdd8PueKHUbomeBnTyVyQxwKRd4KTHPY8MxNf0rKI7Tt4gQSQPJ1
YZD/5xgskPXuYcVP9+RMW8p4nldAGZpn/2OAlsepAmAofmazbCCvBWN0UUc7+rRv
qZNXcj2u/nrWjKPPlgW/mbzU1ce4aC/hw8p3/Mcwygmc8PStFEu8nR7JtwP/yPly
S4WaZXLMHHLGDECSHxhhzf+YZZYGog3luJD1fbiPfSLMPgZw5zGFGrxmEG//2tzw
VqE+rCpjmIXvHx5uGbU6IAq1nCZPjxyo3Ppu6duJHuwsMBANsnA37QtDFUfRJoh1
neTEnPmr5YxNSgTLxbq2SUcjEUoNRezJWWZ4PnIcWZ9zLU0UHf6XI9uvX7544Ek5
g70ewKR5znDrPVuCIx+Obk/DrLuobRwDBoBspbEjf0KRC5+TUmGzeh9OgRnrpRtn
ELSTUuXizM+o9erdwDQzaRsbJZhd1DmUzs5NTcuJCeJbdEHemSD2u/x/rAH/j0Xb
IUv5co83IDqo4+51OurDzx+bxDXio83H52CQzpaLhZAmYR5nOBWfskMbW4n8c299
2Y8W9MNYKiptPmE=
=B1fi
-----END PGP SIGNATURE-----

Attachment: pgpCbHRjNSJ8h.pgp
Description: PGP signature


--- End Message ---

Reply via email to