Prometheus v3.13.2 updates dependencies for two disclosed vulnerabilities and includes related transitive dependency upgrades. It also fixes a PromQL SIGBUS crash when the data disk is full.
Action needed (2)
securityhigh
golang.update for CVE-2026-56852org/x/text golang.updates from v0.38.0 to v0.39.0 in Prometheus v3.13.2 for CVE-2026-56852.org/x/text securityhigh
google.update for GHSA-hrxh-6v49-42gfgolang. org/grpc google.updates from v1.81.1 to v1.82.1 in Prometheus v3.13.2 for GHSA-hrxh-6v49-42gf.golang. org/grpc