CuraDevOps

Plan archived

Prometheus 3.5.5 patches CVE-2026-53606 in UI sanitize-html dep

2026-07-13 14:29 UTC · Releases: prometheus · read the source ↗ #prometheus#security#observability
  • Platform/SRE — Plan: Prometheus is core observability infrastructure; upgrade to v3.5.5 to patch CVE-2026-53606 in the UI’s sanitize-html dependency. Exploitation risk is low (EPSS 0.00, not KEV-listed), so this is routine patching rather than an emergency.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-53606 — CISA KEV: not listed, EPSS 0.00
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.