Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display in github.com/prometheus/prometheus
{ "url": "https://pkg.go.dev/vuln/GO-2026-5381", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-5381.json"