Skip to content
Critical XSS and Code Execution Vulnerabilities in Fedora Prometheus Update

Critical XSS and Code Execution Vulnerabilities in Fedora Prometheus Update

First seen 11 Jul 2026, 23:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 12, 2026 at 23:11 UTC
  • •Fedora's Prometheus update addresses multiple critical vulnerabilities.
  • •Key CVEs include XSS and arbitrary code execution flaws.
  • •Users must update systems immediately using 'dnf' to mitigate risks.

On July 2, 2026, Fedora released an update for Prometheus addressing multiple critical vulnerabilities. The update includes fixes for CVE-2026-40186, CVE-2026-44990, CVE-2026-41567, CVE-2026-53606, and CVE-2026-25681. These vulnerabilities allow for various attack vectors, including Cross-Site Scripting (XSS) and arbitrary code execution via malicious container images. The affected systems include Fedora with Prometheus and associated components. Users are urged to update their systems using the 'dnf' package manager. The vulnerabilities were reported by Mikel Olasagasti Uranga and are now patched. The scope of impact is significant, as these flaws could lead to severe security breaches if exploited. The update is critical for maintaining system integrity and security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-04-15
CVE-2026-40186 published
A vulnerability in Prometheus allows bypass of HTML sanitizer, leading to XSS risks.
Linuxsecurity
2026-05-22
CVE-2026-25681 published
Arbitrary code execution vulnerability via Cross-Site Scripting in golang.org/x/net/html.
Linuxsecurity
2026-06-05
CVE-2026-41567 published
Arbitrary code execution via malicious container image upload in Moby/Docker Engine.
Linuxsecurity
2026-06-12
CVE-2026-44990 published
Stored XSS vulnerability due to HTML sanitizer bypass in Prometheus.
Linuxsecurity
2026-06-12
CVE-2026-53606 published
XSS vulnerability due to insufficient URI scheme validation in sanitize-html.
Linuxsecurity
2026-07-02
Fedora Prometheus update released
An update was released addressing multiple critical vulnerabilities, urging users to upgrade.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-25681 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed