CVE-2026-42151
Red Hat Security Advisory: RHTAS 1.4.3 - CLI Stack Release
Description
A flaw was found in Prometheus, an open-source monitoring system. The `client_secret` field within the Azure Active Directory (AD) remote write OAuth configuration was incorrectly handled as a plain string instead of a secure Secret type. This misconfiguration allowed any user or process with access to the `/-/config` HTTP API endpoint to view the Azure OAuth client secret in plaintext. This vulnerability leads to information disclosure, potentially compromising the security of integrated Azure AD services.
Metrics
Weakness classes (CWE)
CWE-200Class
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
cwe.mitre.org →CWE-312Base
Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
- CVE Modified2026-09-09 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:63103
- CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
- CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:60441
- Reference: https://access.redhat.com/errata/RHSA-2026:60477
- CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
golang1.26.0-0
go
golang.org/x/crypto
golang
crypto0.52.0
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
net0.55.0
prometheus
prometheus2.48.0 – 3.5.3
prometheus
prometheus3.6.0 – 3.11.3
References & sources
- https://go.dev/cl/759940web
- https://go.dev/issue/78566web
- https://groups.google.com/g/golang-announce/c/qcCIEXso47Mweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-39820web
- https://pkg.go.dev/vuln/GO-2026-4986web
- https://access.redhat.com/errata/RHSA-2026:33120web
- https://access.redhat.com/errata/RHSA-2026:33123web
- https://access.redhat.com/errata/RHSA-2026:33142web
- https://access.redhat.com/errata/RHSA-2026:33150web
- https://access.redhat.com/errata/RHSA-2026:33574web
- https://access.redhat.com/errata/RHSA-2026:34364web
- https://access.redhat.com/security/cve/CVE-2026-39820web
- https://bugzilla.redhat.com/show_bug.cgi?id=2467820web
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.jsonweb
- https://access.redhat.com/errata/RHSA-2026:36319web
- https://access.redhat.com/errata/RHSA-2026:36625web
- https://access.redhat.com/errata/RHSA-2026:36754web
- https://access.redhat.com/errata/RHSA-2026:36797web
- https://access.redhat.com/errata/RHSA-2026:23262web
- https://access.redhat.com/errata/RHSA-2026:23264web
Linked CVEs
- CVE-2026-46595
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 10.0 - CVE-2026-42508
A flaw was found in golang.org/x/crypto/ssh/knownhosts.
criticalCVSSv3 9.1 - CVE-2026-42499
A flaw was found in the `net/mail` package within the Go standard library.
highCVSSv3 7.5 - CVE-2026-39835
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 5.3 - CVE-2026-39833
A flaw was found in golang.org/x/crypto/ssh/agent.
criticalCVSSv3 9.1 - CVE-2026-39832
A flaw was found in golang.org/x/crypto/ssh/agent.
criticalCVSSv3 9.1 - CVE-2026-39830
A flaw was found in golang.org/x/crypto/ssh.
criticalCVSSv3 9.1 - CVE-2026-39829
A flaw was found in golang.org/x/crypto/ssh.
highCVSSv3 7.5 - CVE-2026-39828
A flaw was found in golang.org/x/crypto/ssh.
mediumCVSSv3 6.3 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-39820
A flaw was found in the `net/mail` package of the Go programming language.
highCVSSv3 7.5 - CVE-2026-33811
A flaw was found in the `net` package of Go (golang), specifically when using the `LookupCNAME` function with the `cgo` DNS resolver.
highCVSSv3 7.5 - CVE-2026-27145
A flaw was found in the `crypto/x509` package of `golang`.
mediumCVSSv3 6.5