5 open findings · 3 with upstream fix available · 3 after VEX (2 suppressed)
not_affected · vulnerable_code_not_presentnot_affected · vulnerable_code_not_present| Package | Version | Severity | CVE | Fix | Description | VEX |
|---|---|---|---|---|---|---|
| github.com/prometheus/prometheus | v0.311.2-0.20260410083055-07c6232d159b | HIGH | GHSA-8rm2-7qqf-34qm | 0.311.3 | Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | — |
| github.com/prometheus/prometheus | v0.311.2-0.20260410083055-07c6232d159b | HIGH | GHSA-wg65-39gg-5wfj | 0.311.3 | Prometheus Azure AD remote write OAuth client secret exposed via config API | — |
| github.com/aws/aws-sdk-go | v1.55.8 | MEDIUM | GO-2022-0646 | — | A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without compu | VEX |
| github.com/prometheus/prometheus | v0.311.2-0.20260410083055-07c6232d159b | MEDIUM | GHSA-fw8g-cg8f-9j28 | 0.311.3 | Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display | — |
| github.com/aws/aws-sdk-go | v1.55.8 | LOW | GO-2022-0635 | — | A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bu | VEX |