Alerts This Week
Warning Icon 1 745
Alerts This Week
Warning Icon 1 745

Fedora 43 Prometheus Critical Denial of Service Threats 2026-dfc0e362e6

fedora
Calendar Grey June 22, 2026
Dist Fedora Esm H88
Explore Fedora 43 Prometheus update addressing critical Denial of Service and exposure risks due to misconfigurations.
Update to 3.12.0

Summary

The Prometheus monitoring system and time series database.

Update Information:

Update to 3.12.0

Change Log

* Fri Jun 12 2026 Mikel Olasagasti Uranga - 3.12.0-1 - Update to 3.12.0 - Closes rhbz#2482792

References


[ 1 ] Bug #2481306 - CVE-2026-42154 prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481306 [ 2 ] Bug #2481308 - CVE-2026-42151 prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481308 [ 3 ] Bug #2486235 - CVE-2026-45287 prometheus: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486235

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dfc0e362e6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: prometheus
Product: Fedora 43
Version: 3.12.0
Release: 1.fc43
Summary: Prometheus monitoring system and time series database

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here