CVE-2026-42151 | Prometheus up to 3.5.2/3.11.2 HTTP API Endpoint storage/remote/azuread client_secret information disclosure (GHSA-wg65-39gg-5wfj / EUVD-2026-27089)
A vulnerability identified as problematic has been detected in Prometheus up to 3.5.2/3.11.2. This issue affects the function client_secret of the file storage/remote/azuread of the component HTTP API Endpoint. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-42151. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.