Skip to content

fix(monitor): bump prometheus to v3.11.3 and thanos to v0.41.0#121

Merged
kuny0707 merged 1 commit into
tronprotocol:developfrom
Sunny6889:fix/cve-2026-42154-bump-prom-thanos
May 14, 2026
Merged

fix(monitor): bump prometheus to v3.11.3 and thanos to v0.41.0#121
kuny0707 merged 1 commit into
tronprotocol:developfrom
Sunny6889:fix/cve-2026-42154-bump-prom-thanos

Conversation

@Sunny6889
Copy link
Copy Markdown
Contributor

Prometheus v3.10.0 falls in the vulnerable range of CVE-2026-42154 (GHSA-8rm2-7qqf-34qm), a remote_read DoS via crafted snappy payload. Bump to v3.11.3 which contains the fix. Thanos v0.33.0 is also upgraded to the latest stable v0.41.0.

What does this PR do?

Why are these changes required?

This PR has been tested by:

  • Unit Tests
  • Manual Testing

Follow up

Extra details

Prometheus v3.10.0 falls in the vulnerable range of CVE-2026-42154
(GHSA-8rm2-7qqf-34qm), a remote_read DoS via crafted snappy payload.
Bump to v3.11.3 which contains the fix. Thanos v0.33.0 is also
upgraded to the latest stable v0.41.0.
@kuny0707 kuny0707 merged commit 77c35a8 into tronprotocol:develop May 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants