prom/prometheus:v3.14.0

container image

Deployed by 1 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.

Radar Score

69
worst finding Medium
Critical
0
High
0
Medium
1
Low
9
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

10 findings on digest 5ce7540c3c00 · scanned 3 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of prom/prometheus:v3.14.0 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

3 Sept 2026 · Radar Score 69 · OSV as of 3 Sept 2026 · digest 5ce7540c3c00
history since 3 Sept 2026

Findings

10 distinct on the current digest

Findings for digest 5ce7540c3c00 as scanned on 3 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 3 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GHSA-8rm2-7qqf-34qm

Prometheus: Remote read endpoint allows denial of service via crafted snappy payload

github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang0.305.215/1000.008 (54th pct)3 Sept 2026
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.82.1golang1.83.19/1003 Sept 2026
GHSA-vffh-x6r8-xx99

Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer

github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang0.311.2-0.20260410083055-07c6232d159b8/1000.003 (17th pct)3 Sept 2026
GHSA-fw8g-cg8f-9j28

Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display

github.com/prometheus/prometheus@v0.0.0-20260817133844-d7598b714141+dirtygolang0.311.38/1000.002 (10th pct)3 Sept 2026
GO-2022-0646

CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.8golangno fix listed6/1000.003 (27th pct)3 Sept 2026
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.54.0golang0.55.06/1000.003 (25th pct)3 Sept 2026
GO-2022-0635

In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.8golangno fix listed5/1000.002 (14th pct)3 Sept 2026
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.54.0golangno fix listed4/1003 Sept 2026
GO-2026-6354

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.54.0golang0.56.04/1003 Sept 2026
GO-2026-6355

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.54.0golang0.56.04/1003 Sept 2026

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v3.14.0current5ce7540c3c00linux/amd643 Sept 20263 Sept 202669

Used by

Charts whose default render references this repository, with the workload that carries it.

syft 1.42.1 · scanned 3 Sept 2026 · advisories as of 3 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.