Database/Control plane, storage & DevOps
Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memory
Impact
The remote read endpoint allocates memory based on the decoded length declared in a snappy-compressed request body without checking it against anything, so a tiny unauthenticated request triggers a very large heap allocation. Sent concurrently, this exhausts memory and kills the Prometheus process - and on a node with a container memory limit it will be the OOM killer that does it. For a GPU fleet this takes out the metrics path that alerting, capacity planning and per-tenant GPU accounting run on, and a Prometheus that is being repeatedly crashed will not stay up long enough to catch up on scrapes. Only servers with the remote read endpoint reachable are exposed.
Who can reach it
Anyone who can send an HTTP request to /api/v1/read on the Prometheus server. No authentication is required.
What to do
Upgrade to Prometheus 3.5.3 or 3.11.3 (or the corresponding Red Hat errata) and restart the process. If a patch window is not immediate, put the remote read endpoint behind an authenticating proxy or firewall it off from anything but the intended readers; disabling remote read entirely is the strongest stopgap where nothing depends on it.
References
Related entries
- OpenTelemetry JS Prometheus exporter: a malformed request URI crashes the whole Node.js processCVE-2026-44902 · OpenTelemetry JS Prometheus exporter (@opentelemetry/exporter-prometheus, also via sdk-node)High
- Suricata: unbounded NFS parser state lets crafted traffic exhaust sensor memoryCVE-2026-45766 · Suricata (NFS application-layer parser)High
- Airflow FTP provider: FTPS data channel sent in cleartext because PROT P was never issuedCVE-2026-49486 · Apache Airflow FTP provider (FTPSHook data channel)High
- rclone (local backend, --links): When rclone copies from an untrusted remote with --links, it recreates symlinksCVE-2026-54572 · rclone (local backend, --links)High
- Jenkins Script Security Plugin: Groovy sandbox escape via AST annotation extensions memberCVE-2026-57281 · Jenkins Script Security Plugin (Groovy sandbox, AST transformation annotations)High
- Airflow Backfill API: any Dag editor can read and cancel backfills belonging to other DagsCVE-2026-68968 · Apache Airflow Backfill API (authorization dependency id parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.