Package
grafana-12.2
Component
github.com/prometheus/prometheus
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Remediating this CVE requires bumping github.com/prometheus/prometheus to v0.311.3, which restructured/removed the storage/remote/otlptranslator/prometheus and tsdb/errors packages. Grafana transitively depends on github.com/grafana/loki/v3 (v3.2.1), which still imports both removed packages, so the bump cannot be applied until either upstream Grafana bumps Loki or upstream Loki adopts the new prometheus package layout.
Status