FlawAtlas
Search the atlas
SUSE-SU-2026:1008-1 Not scored

Security update for Prometheus

This update for Prometheus fixes the following issues: golang-github-prometheus-alertmanager, golang-github-prometheus-node_exporter: - Internal changes to fix build issues with no impact for customers golang-github-prometheus-prometheus: - Security issues fixed: * CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841) * CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442) * CVE-2025-13465: Bump lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329) * CVE-2025-12816: Interpretation conflict vulnerability allowing bypassing cryptographic verifications (bsc#1255588) - Version update from 2.53.4 to 3.5.0 with the following highlighted changes (jsc#PED-13824): * Modernized Interface: Introduced a brand-new UI * Enhanced Cloud and Auth: Added unified AWS service discovery (EC2, ECS, Lightsail) and Azure Workload Identity support for more secure, native cloudauthentication. * Performance Standards: Fully integrated OpenTelemetry (OTLP) ingestion and moved Native Histograms from experimental to a stable feature. * Advanced Data Export: Rolled out Remote Write 2.0, offering better performance and metadata handling when sending data to external systems. * Query Power: Added new PromQL functions (like first_over_time and last_over_time) and optimization for grouping operations. * Better Visibility: The UI now displays detailed relabeling steps, scrape intervals, and timeouts, making it easier to troubleshoot why targets aren't reporting correctly. * Critical Fixes: Resolved significant memory leaks related to query logging and fixed bugs where targets were accidentally being scraped multiple times.

Exploit probability Not scored
Published March 25, 2026
Required by Not available
Last source change March 26, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Module for Basesystem 15 SP7 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Module for Package Hub 15 SP7 golang-github-prometheus-alertmanager
SUSE:Linux Enterprise Module for Package Hub 15 SP7 golang-github-prometheus-prometheus
SUSE:Linux Enterprise Server 15 SP4-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server 15 SP5-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server 15 SP6-LTSS golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 golang-github-prometheus-node_exporter
SUSE:Linux Enterprise Server for SAP Applications 15 SP6 golang-github-prometheus-node_exporter
SUSE:Manager Client Tools 15 golang-github-prometheus-alertmanager
SUSE:Manager Client Tools for SLE Micro 5 golang-github-prometheus-node_exporter
openSUSE:Leap 15.6 golang-github-prometheus-alertmanager
openSUSE:Leap 15.6 golang-github-prometheus-node_exporter
openSUSE:Leap 15.6 golang-github-prometheus-prometheus

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1008-1

This update for Prometheus fixes the following issues: golang-github-prometheus-alertmanager, golang-github-prometheus-node_exporter: - Internal changes to fix build issues with no impact for customers golang-github-prometheus-prometheus: - Security issues fixed: * CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841) * CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442) * CVE-2025-13465: Bump lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329) * CVE-2025-12816: Interpretation conflict vulnerability allowing bypassing cryptographic verifications (bsc#1255588) - Version update from 2.53.4 to 3.5.0 with the following highlighted changes (jsc#PED-13824): * Modernized Interface: Introduced a brand-new UI * Enhanced Cloud and Auth: Added unified AWS service discovery (EC2, ECS, Lightsail) and Azure Workload Identity support for more secure, native cloudauthentication. * Performance Standards: Fully integrated OpenTelemetry (OTLP) ingestion and moved Native Histograms from experimental to a stable feature. * Advanced Data Export: Rolled out Remote Write 2.0, offering better performance and metadata handling when sending data to external systems. * Query Power: Added new PromQL functions (like first_over_time and last_over_time) and optimization for grouping operations. * Better Visibility: The UI now displays detailed relabeling steps, scrape intervals, and timeouts, making it easier to troubleshoot why targets aren't reporting correctly. * Critical Fixes: Resolved significant memory leaks related to query logging and fixed bugs where targets were accidentally being scraped multiple times.

View original source

05 / REFERENCES

Further evidence