prometheus29.27.0

Helm chart
prometheus-community repositoryon Artifact Hub 553#5 by starsofficialverified publisher

Prometheus is a monitoring system and time series database.

version 29.27.0kube >=1.19.0-0app version v3.14.0
README badge
[![Radar Score](https://charts.stackradar.io/badge/prometheus-community/prometheus.svg)](https://charts.stackradar.io/charts/prometheus-community/prometheus)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

Radar Score

254
worst finding Low
Critical
0
High
0
Medium
0
Low
40
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

40 findings over 4 of 6 images measured · scored 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of 29.27.0, one sample per day, last 90 days. Hover a point for its date and advisory data.

2 Sept 2026 · Radar Score 254 · OSV as of 2 Sept 2026
history since 2 Sept 2026

Score moves

A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves

Fewer than two samples so far.

Findings

25 distinct across the version’s images

AdvisoryPackageFixed inContributionEPSSSinceDigests
GHSA-hrxh-6v49-42gf

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

google.golang.org/grpc@v1.79.3golang1.82.19/1002 Sept 202642cfe3723a5f
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.82.1golang1.83.19/1002 Sept 202642cfe3723a5f690c7b525f43
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.26.5golang1.25.138/1000.007 (50th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.26.3golang1.25.117/1000.006 (46th pct)2 Sept 202674fa117cef2d
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.26.5golang1.25.137/1000.006 (45th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.26.5golang1.25.137/1000.006 (45th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.26.5golang1.25.137/1000.006 (45th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.26.5golang1.25.137/1000.006 (45th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.26.3golang1.25.117/1000.006 (44th pct)2 Sept 202674fa117cef2d
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.55.0golang0.56.07/1000.005 (44th pct)2 Sept 202674fa117cef2d
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.5golang1.26.67/1000.005 (44th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.26.5golang1.25.137/1000.005 (42th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.37.0golang0.39.07/1000.005 (39th pct)2 Sept 202674fa117cef2d
GHSA-gcjh-h69q-9w9g

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

github.com/google/cel-go@v0.26.0golang0.29.06/1002 Sept 202642cfe3723a5f
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.26.3golang1.25.126/1000.004 (31th pct)2 Sept 202674fa117cef2d
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.26.3golang1.25.116/1000.004 (30th pct)2 Sept 202674fa117cef2d
GO-2026-5158

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

go.opentelemetry.io/otel@v1.43.0golang1.42.06/1000.003 (26th pct)2 Sept 202642cfe3723a5f
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.54.0golang0.55.06/1000.003 (25th pct)2 Sept 20261b4e4438faca42cfe3723a5f690c7b525f4374fa117cef2d
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.26.5golang1.25.136/1000.003 (23th pct)2 Sept 20261b4e4438faca74fa117cef2d
GO-2026-6180

Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb

golang.org/x/mod@v0.38.0golang0.40.06/1000.003 (22th pct)2 Sept 2026690c7b525f43
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.26.3golang1.25.125/1000.002 (14th pct)2 Sept 202674fa117cef2d
GO-2026-6179

Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog

golang.org/x/mod@v0.38.0golang0.40.04/1000.001 (1th pct)2 Sept 2026690c7b525f43
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.54.0golangno fix listed4/1002 Sept 20261b4e4438faca42cfe3723a5f690c7b525f4374fa117cef2d
GO-2026-6061

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

google.golang.org/grpc@v1.79.3golang1.82.14/1002 Sept 202642cfe3723a5f
GO-2026-6094

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

github.com/google/cel-go@v0.26.0golang0.30.04/1002 Sept 202642cfe3723a5f

Workloads and images

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

ContainerImageTagDigestRadar Score
DaemonSet candidate-prometheus-node-exporter
node-exporterquay.io/prometheus/node-exporterv1.12.11b4e4438faca66
Deployment candidate-kube-state-metrics
kube-state-metricsregistry.k8s.io/kube-state-metrics/kube-state-metricsv2.20.042cfe3723a5f48
Deployment candidate-prometheus-pushgateway
pushgatewayquay.io/prometheus/pushgatewayv1.11.374fa117cef2d112
Deployment candidate-prometheus-server
prometheus-server-configmap-reloadquay.io/prometheus-operator/prometheus-config-reloaderv0.93.1428f088fe6fenot yet scanned
prometheus-serverquay.io/prometheus/prometheusv3.14.05ce7540c3c00not yet scanned
StatefulSet candidate-alertmanager
alertmanagerquay.io/prometheus/alertmanagerv0.34.0690c7b525f4328

Unmeasured images (2)

  • quay.io/prometheus-operator/prometheus-config-reloader:v0.93.1inventoried, not yet matched
  • quay.io/prometheus/prometheus:v3.14.0inventoried, not yet matched

Indexed versions

The latest version and the previous major, as selected nightly from the repository’s index.

VersionApp versionRadar ScoreBandMeasuredRender
29.27.0latestv3.14.0254Low4 / 6rendered 2 Sept 2026
28.16.0previous majorv3.11.03,263Medium6 / 6rendered 2 Sept 2026

helm v3.16.4 · syft 1.42.1 · rendered 2 Sept 2026 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.