[GHSA-vffh-x6r8-xx99] [CVE-2026-40179] Doesn't show all remediated versions (particularly v3.5.2's go counterpart v0.305.2)

Open Beginner friendly
#7,537 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
70/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
go, prometheus
Domain
security

Research direction

Start with advisory GHSA-vffh-x6r8-xx99 and compare its patched-version metadata with the Prometheus v3.5.2 release and the Go module version cited in the issue. Done means the advisory accurately lists both remediated version lines, including 0.305.2 alongside 0.311.2.

Written by the indexing model from the issue text.

Description

Considering the advisory https://github.com/advisories/GHSA-vffh-x6r8-xx99

We see
https://github.com/prometheus/prometheus/releases/tag/v3.5.2 remediates this, but the patched versions don't accurately reflect this fact (they only show the 0.311.2 patch, not the 0.305.2 LTS patch for the Go module)

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 20h
Merged PRs (30d)
49

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.