grafana-pyroscope-1.19
github.com/prometheus/prometheus
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
GHSA-vffh-x6r8-xx99 is an XSS in Prometheus's React web UI (web/ui/*.tsx). This binary imports github.com/prometheus/prometheus only as a Go library (model/, parser, etc.) and does not import prometheus/web; the vulnerable JavaScript is not embedded in the binary.
Status