prom/prometheus:v3.14.0
container imageDeployed by 1 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 1
- Low
- 9
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
10 findings on digest 5ce7540c3c00 · scanned 3 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of prom/prometheus:v3.14.0 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
10 distinct on the current digest
Findings for digest 5ce7540c3c00 as scanned on 3 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 3 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| GHSA-8rm2-7qqf-34qm Prometheus: Remote read endpoint allows denial of service via crafted snappy payload | github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang | 0.305.2 | 15/100 | 0.008 (54th pct) | 3 Sept 2026 |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.82.1golang | 1.83.1 | 9/100 | — | 3 Sept 2026 |
| GHSA-vffh-x6r8-xx99 Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer | github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang | 0.311.2-0.20260410083055-07c6232d159b | 8/100 | 0.003 (17th pct) | 3 Sept 2026 |
| GHSA-fw8g-cg8f-9j28 Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display | github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang | 0.311.3 | 8/100 | 0.002 (10th pct) | 3 Sept 2026 |
| GO-2022-0646 CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go | github.com/aws/aws-sdk-go@v1.55.8golang | no fix listed | 6/100 | 0.003 (27th pct) | 3 Sept 2026 |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.54.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 3 Sept 2026 |
| GO-2022-0635 In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go | github.com/aws/aws-sdk-go@v1.55.8golang | no fix listed | 5/100 | 0.002 (14th pct) | 3 Sept 2026 |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.54.0golang | no fix listed | 4/100 | — | 3 Sept 2026 |
| GO-2026-6354 Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.54.0golang | 0.56.0 | 4/100 | — | 3 Sept 2026 |
| GO-2026-6355 Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.54.0golang | 0.56.0 | 4/100 | — | 3 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v3.14.0current | 5ce7540c3c00 | linux/amd64 | 3 Sept 2026 | 3 Sept 2026 | 69 |