Package
plutono
Component
github.com/prometheus/prometheus
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This vulnerability exists in Prometheus server-side remote-read handling exposed through the /api/v1/read HTTP endpoint, but Plutono does not include the vulnerable storage/remote or web/api/v1 server packages in its binaries. Plutono imports only non-server Prometheus libraries transitively and does not host the vulnerable /api/v1/read endpoint. Verified by build dependency analysis and binary analysis.
Status