CVE-2026-42154 | Prometheus up to 3.5.2/3.11.2 Remote Read Endpoint /api/v1/read resource consumption (GHSA-8rm2-7qqf-34qm / EUVD-2026-27091)
A vulnerability labeled as problematic has been found in Prometheus up to 3.5.2/3.11.2. Impacted is an unknown function of the file /api/v1/read of the component Remote Read Endpoint. The manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2026-42154. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.