logo

Critical XSS and Code Execution Vulnerabilities in Fedora Prometheus Update

ID: 0e28883f-f609-531c-b384-c7193ef9d49c

STIX ID: report--0e28883f-f609-531c-b384-c7193ef9d49c

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-07-11

Date Updated: 2026-07-17

...
...

Fedora released a critical Prometheus update on July 2, 2026, addressing multiple vulnerabilities (CVE-2026-40186, CVE-2026-44990, CVE-2026-41567, CVE-2026-53606, CVE-2026-25681) that include cross-site scripting and potential arbitrary code execution via malicious container images; users are strongly urged to apply the patched packages using dnf to mitigate significant security risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.