/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-m4v2-64jf-4976

Published

Last updated

https://images.chainguard.dev/security/CGA-m4v2-64jf-4976
Package

prometheus-operator

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2019-3826
  • GHSA-3m87-5598-2v4f

Severity

6.1

Medium

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2019-3826

Updates

Status

Not affected

Justification

Component not present

Impact

Prometheus ships a Go (Golang) library with a versioning scheme that follows the 0.x format. However, the Prometheus application itself uses a versioning scheme based on 1.x, 2.x, etc. The vulnerability identified in CVE-2019-3826 is specifically associated with the Prometheus application, not the Golang library.

Status

Not affected

Justification

Vulnerable code not present

Impact

This CVE only impacts prometheus 2.7 but our prometheus-operator is using v0.46.0 Go library which is in fact prothemeus 2.46


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing