logo

300,000+ Prometheus Servers and Exporters Exposed to DoS Attacks

ID: f07c4b5e-76b7-5815-93a7-a04e6371b5ae

STIX ID: report--f07c4b5e-76b7-5815-93a7-a04e6371b5ae

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2024-12-12

Date Updated: 2026-04-26

...
...

This research identifies significant security risks in the Prometheus stack: widespread internet exposure of Prometheus servers and exporters (~336k assets) leading to sensitive information disclosure; exploitable /debug/pprof endpoints enabling DoS attacks that can crash hosts or Kubernetes pods; and RepoJacking vulnerabilities in exporters that could allow supply-chain remote code execution. The report includes Shodan scan counts, PoC for DoS, examples of leaked secrets and exposed subdomains/images, and recommends authentication, limiting public exposure, disabling or restricting pprof, resource limits, and validating open-source links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.