# Prometheus changelog > The monitoring system and time-series database. - Vendor: Prometheus - Category: Developer Tools - Official site: https://prometheus.io - Tracked by: What's New (https://whatsnew.fyi/product/prometheus) - Harvested from: GitHub (prometheus/prometheus) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. ## Releases ### v3.13.2 — 3.13.2 / 2026-07-29 - Date: 2026-07-30 - Version: v3.13.2 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.2 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.13.2 - **security** — Bump golang.org/x/text to v0.39.0 (CVE-2026-56852) and google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf) - **fixed** — PromQL: Preallocate the active query tracker file to avoid SIGBUS crashes when the data disk is full ##### What's Changed - [SECURITY] Bump golang.org/x/text to v0.39.0 (CVE-2026-56852) and google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf). #19290 by @krajorama - [BUGFIX] PromQL: Preallocate the active query tracker file to avoid SIGBUS crashes when the data disk is full. #19289 by @akshajrawat **Full Changelog**: https://github.com/prometheus/prometheus/compare/v3.13.1...v3.13.2 ### v3.13.1 — 3.13.1 / 2026-07-10 - Date: 2026-07-10 - Version: v3.13.1 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.1 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.13.1 - **fixed** — TSDB: Fix the head-chunk cache returning samples from the wrong chunk, or spurious not-found errors, to range queries after head-chunk truncation This is a bugfix release for 3.13 LTS. - [BUGFIX] TSDB: Fix the head-chunk cache returning samples from the wrong chunk, or spurious not-found errors, to range queries after head-chunk truncation. #19134 ### v3.5.5 — 3.5.5 / 2026-07-09 - Date: 2026-07-09 - Version: v3.5.5 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.5.5 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.5.5 - **security** — Bump sanitize-html to v2.17.5 to fix CVE-2026-53606 in UI dependency This release is built with Go 1.25.12 and fixes a security issue in a UI dependency. - [SECURITY] UI: Bump `sanitize-html` to v2.17.5 to fix CVE-2026-53606. #19060 ### v3.13.0-rc.0 — 3.13.0-rc.0 / 2026-06-18 - Date: 2026-07-09 - Version: v3.13.0-rc.0 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0-rc.0 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.13.0-rc.0 - Labels: Pre-release - **security** — Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990) - **changed** — Use SHA-256 instead of SHA-1 to generate rule group pagination tokens - **security** — Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery (CVE-2025-4673 CVE-2023-45289) - **changed** — Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory - **changed** — Rename the min() and max() duration-expression functions to min_of() and max_of() to avoid confusion with the min and max aggregate operators - **added** — Add experimental search endpoints to search metric names, label names, and label values - **added** — Add ability to filter RDS instances in Discovery/AWS - **added** — Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values - **added** — Add support for smoothed/anchored rate with native histograms - **added** — Expose per-query samplesRead in the query stats response and add the prometheus_engine_query_samples_read_total engine counter - **added** — Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling - **added** — Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding at runtime - **added** — Add Certificate support for ingesting data into an Azure Monitor Workspace in remote_write - **added** — Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of scrape configuration via relabeling - **changed** — Container images are now also published to the GitHub Container Registry (ghcr.io) - **changed** — Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal - **changed** — Improve autocompletion after closing a function bracket - **fixed** — Fix failure when processing an AWS RDS cluster without instances - **fixed** — Fix race condition in initTime that could cause ErrOutOfBounds - **fixed** — Fix range query whose end was not aligned to step causing subqueries to evaluate past the parent's last actual step - **fixed** — Fix range query containing an at-modifier-unsafe function over a range-vector with an @ modifier under-counting totalQueryableSamples - **fixed** — Fix fill_left/fill_right producing missing samples in range queries when using group_left/group_right - [SECURITY] UI: Bump `sanitize-html` to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697 - [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927 - [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949 - [CHANGE] promtool: Relative file paths in the file passed to `--http.config.file` are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949 - [CHANGE] PromQL: Rename the `min()` and `max()` duration-expression functions (experimental feature flag `experimental-duration-expr`) to `min_of()` and `max_of()` to avoid confusion with the `min` and `max` aggregate operators. #18687 - [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573 - [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859 - [FEATURE] PromQL: Add `min_of(a, b)` and `max_of(a, b)` scalar experimental functions, returning the smaller or larger of two scalar values. #18687 - [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564 - [FEATURE] PromQL: Expose per-query `samplesRead` (and `samplesReadPerStep` with `stats=all` and the `promql-per-step-stats` feature flag) in the query stats response, and add the `prometheus_engine_query_samples_read_total` engine counter. `samplesRead` reflects storage I/O distinct from `totalQueryableSamples`, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081 - [FEATURE] Scrape: Add `__convert_classic_histograms_to_nhcb__` internal label to allow per-target override of `convert_classic_histograms_to_nhcb` scrape configuration via relabeling. #18840 - [FEATURE] TSDB: Add `storage.tsdb.chunk_encoding.floats` configuration field to select float chunk encoding (`xor` or `xor2`) at runtime, independently of the `--enable-feature=xor2-encoding` flag. #18769 - [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217 - [FEATURE] Scrape: Add `__always_scrape_classic_histograms__` and `__scrape_native_histograms__` internal labels to allow per-target override of the `always_scrape_classic_histograms` and `scrape_native_histograms` scrape configuration via relabeling. #18929 - [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791 - [ENHANCEMENT] PromQL: Prettify `fill_left(x) fill_right(x)` as `fill(x)` when both fill values are equal. #18851 - [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894 - [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540 - [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699 - [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (`--enable-feature=created-timestamp-zero-ingestion`). #18813 - [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845 - [BUGFIX] Fix race condition in initTime that could cause ErrOutOfBounds. #18629 - [BUGFIX] PromQL: A range query whose `end` was not aligned to `step` caused subqueries inside it to evaluate past the parent's last actual step, inflating `peakSamples` in the query stats and against the `query.max-samples` limit, and wasting storage I/O reading samples that were never used in the _[Truncated at 4000 characters — full notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0-rc.0]_ ### v3.13.0 — 3.13.0 / 2026-07-01 - Date: 2026-07-01 - Version: v3.13.0 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.13.0 - **security** — Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990) - **changed** — Third-party npm dependency licenses are now embedded in the Prometheus binary and served at /assets/third-party-licenses.txt - **changed** — Use SHA-256 instead of SHA-1 to generate rule group pagination tokens - **security** — Credentials are no longer forwarded when following a redirect to a different host in HTTP clients (CVE-2025-4673 CVE-2023-45289) - **changed** — Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory - **changed** — Rename the min() and max() duration-expression functions to min_of() and max_of() to avoid confusion with the min and max aggregate operators - **added** — Add experimental search endpoints to search metric names, label names, and label values - **added** — Add ability to filter RDS instances in Discovery/AWS - **added** — Add min_of(a, b) and max_of(a, b) scalar experimental functions - **added** — Add support for smoothed/anchored rate with native histograms - **added** — Expose per-query samplesRead in the query stats response and add the prometheus_engine_query_samples_read_total engine counter - **added** — Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling - **added** — Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding at runtime - **added** — Add Certificate support for ingesting data into an Azure Monitor Workspace in remote_write - **added** — Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of scrape configuration via relabeling - **changed** — Container images are now also published to the GitHub Container Registry (ghcr.io) - **changed** — Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal - **fixed** — Fix failure when processing an AWS RDS cluster without instances - **fixed** — Fix race condition in initTime that could cause ErrOutOfBounds - **fixed** — Fix range query with end not aligned to step causing subqueries to evaluate past the parent's last actual step - **fixed** — Fix range query containing an at-modifier-unsafe function over a range-vector with an @ modifier under-counting totalQueryableSamples This is a Long Term Support [LTS](https://prometheus.io/docs/introduction/release-cycle/) release. - [SECURITY] UI: Bump `sanitize-html` to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697 - [CHANGE] UI: Third-party npm dependency licenses are now embedded in the Prometheus binary and served at `/assets/third-party-licenses.txt`, replacing the `npm_licenses.tar.bz2` archive previously shipped in release tarballs and container images. #18997 - [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927 - [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949 - [CHANGE] promtool: Relative file paths in the file passed to `--http.config.file` are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949 - [CHANGE] PromQL: Rename the `min()` and `max()` duration-expression functions (experimental feature flag `experimental-duration-expr`) to `min_of()` and `max_of()` to avoid confusion with the `min` and `max` aggregate operators. #18687 - [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573 - [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859 - [FEATURE] PromQL: Add `min_of(a, b)` and `max_of(a, b)` scalar experimental functions, returning the smaller or larger of two scalar values. #18687 - [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564 - [FEATURE] PromQL: Expose per-query `samplesRead` (and `samplesReadPerStep` with `stats=all` and the `promql-per-step-stats` feature flag) in the query stats response, and add the `prometheus_engine_query_samples_read_total` engine counter. `samplesRead` reflects storage I/O distinct from `totalQueryableSamples`, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081 - [FEATURE] Scrape: Add `__convert_classic_histograms_to_nhcb__` internal label to allow per-target override of `convert_classic_histograms_to_nhcb` scrape configuration via relabeling. #18840 - [FEATURE] TSDB: Add `storage.tsdb.chunk_encoding.floats` configuration field to select float chunk encoding (`xor` or `xor2`) at runtime, independently of the `--enable-feature=xor2-encoding` flag. #18769 - [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217 - [FEATURE] Scrape: Add `__always_scrape_classic_histograms__` and `__scrape_native_histograms__` internal labels to allow per-target override of the `always_scrape_classic_histograms` and `scrape_native_histograms` scrape configuration via relabeling. #18929 - [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791 - [ENHANCEMENT] PromQL: Prettify `fill_left(x) fill_right(x)` as `fill(x)` when both fill values are equal. #18851 - [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894 - [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540 - [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699 - [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (`--enable-feature=created-timestamp-zero-ingestion`). #18813 - [BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845 - [BUGFIX] Fix race cond _[Truncated at 4000 characters — full notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0]_ ### v3.13.0-rc.1 — 3.13.0-rc.1 / 2026-06-22 - Date: 2026-06-22 - Version: v3.13.0-rc.1 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0-rc.1 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.13.0-rc.1 - Labels: Pre-release - **security** — Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990) - **changed** — Use SHA-256 instead of SHA-1 to generate rule group pagination tokens - **security** — Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery (CVE-2025-4673 CVE-2023-45289) - **changed** — Relative file paths in the file passed to promtool --http.config.file are now resolved relative to that config file's directory instead of its parent directory - **changed** — Rename the min() and max() duration-expression functions (experimental feature flag experimental-duration-expr) to min_of() and max_of() to avoid confusion with the min and max aggregate operators - **added** — Add experimental search endpoints to search metric names, label names, and label values - **added** — Add ability to filter RDS instances in AWS Discovery - **added** — Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values - **added** — Add support for smoothed/anchored rate with native histograms - **added** — Expose per-query samplesRead (and samplesReadPerStep with stats=all and the promql-per-step-stats feature flag) in the query stats response, and add the prometheus_engine_query_samples_read_total engine counter - **added** — Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling - **added** — Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding (xor or xor2) at runtime, independently of the --enable-feature=xor2-encoding flag - **added** — Add Certificate support for ingesting data into an Azure Monitor Workspace in remote_write - **added** — Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of the always_scrape_classic_histograms and scrape_native_histograms scrape configuration via relabeling - **changed** — Third-party npm dependency licenses are now embedded in the Prometheus binary and served at /assets/third-party-licenses.txt, replacing the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images - **changed** — Container images are now also published to the GitHub Container Registry (ghcr.io) - **changed** — Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal - **changed** — Improve autocompletion after closing a function bracket in the UI - **fixed** — Fix failure when processing an AWS RDS cluster without instances in Discovery/AWS - **fixed** — Fix race condition in initTime that could cause ErrOutOfBounds Release notes of the 3.13-rc.1 release: The 3.13.0-rc.0 release was only partially successful due to the migration from NPM to PNPM and subsequent CI issues, so most of the changes in this release candidate are CI/build-related. The only user-facing change is: - [CHANGE] UI: Third-party npm dependency licenses are now embedded in the Prometheus binary and served at `/assets/third-party-licenses.txt`, replacing the `npm_licenses.tar.bz2` archive previously shipped in release tarballs and container images. #18997 Release notes of the 3.13-rc.0 release, as it was not published in partial state: - [SECURITY] UI: Bump `sanitize-html` to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697 - [CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927 - [CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673 CVE-2023-45289). #18949 - [CHANGE] promtool: Relative file paths in the file passed to `--http.config.file` are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949 - [CHANGE] PromQL: Rename the `min()` and `max()` duration-expression functions (experimental feature flag `experimental-duration-expr`) to `min_of()` and `max_of()` to avoid confusion with the `min` and `max` aggregate operators. #18687 - [FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573 - [FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859 - [FEATURE] PromQL: Add `min_of(a, b)` and `max_of(a, b)` scalar experimental functions, returning the smaller or larger of two scalar values. #18687 - [FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564 - [FEATURE] PromQL: Expose per-query `samplesRead` (and `samplesReadPerStep` with `stats=all` and the `promql-per-step-stats` feature flag) in the query stats response, and add the `prometheus_engine_query_samples_read_total` engine counter. `samplesRead` reflects storage I/O distinct from `totalQueryableSamples`, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081 - [FEATURE] Scrape: Add `__convert_classic_histograms_to_nhcb__` internal label to allow per-target override of `convert_classic_histograms_to_nhcb` scrape configuration via relabeling. #18840 - [FEATURE] TSDB: Add `storage.tsdb.chunk_encoding.floats` configuration field to select float chunk encoding (`xor` or `xor2`) at runtime, independently of the `--enable-feature=xor2-encoding` flag. #18769 - [FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217 - [FEATURE] Scrape: Add `__always_scrape_classic_histograms__` and `__scrape_native_histograms__` internal labels to allow per-target override of the `always_scrape_classic_histograms` and `scrape_native_histograms` scrape configuration via relabeling. #18929 - [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791 - [ENHANCEMENT] PromQL: Prettify `fill_left(x) fill_right(x)` as `fill(x)` when both fill values are equal. #18851 - [ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894 - [PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540 - [PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699 - [PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployment _[Truncated at 4000 characters — full notes: https://github.com/prometheus/prometheus/releases/tag/v3.13.0-rc.1]_ ### v3.5.4 — 3.5.4 / 2026-06-17 - Date: 2026-06-17 - Version: v3.5.4 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.5.4 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.5.4 - **security** — Fix secrets being exposed in plaintext via /-/config endpoint in STACKIT SD - **security** — Bump golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0 to fix reported CVEs - **security** — Bump mantine-ui dependencies (react-router-dom, vitest, vite, postcss) to patched versions to resolve security advisories - **added** — Container images are now also published to the GitHub Container Registry (ghcr.io) This release fixes multiple security issues. - [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via `/-/config` endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18650 - [SECURITY] Dependencies: Bump `golang.org/x/net` to v0.55.0 and OpenTelemetry to v1.43.0 to fix reported CVEs (GO-2026-5026, GO-2026-4918, GO-2026-4985). #18934 - [SECURITY] UI: Bump mantine-ui dependencies (`react-router-dom`, `vitest`, `vite`, `postcss`) to their patched versions to resolve security advisories. #18935 - [ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18792 ### v3.12.0 — 3.12.0 / 2026-05-28 - Date: 2026-05-28 - Version: v3.12.0 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.12.0 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.12.0 - **security** — Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds 32MB - **security** — Fix secrets being exposed in plaintext via /-/config endpoint in STACKIT SD - **added** — Add /api/v1/status/self_metrics endpoint returning the current state of the Prometheus server's own metrics - **added** — Add DigitalOcean Managed Databases service discovery - **added** — Add support for the aix/ppc64 compilation target - **added** — Add Outscale VM service discovery (outscale_sd_configs) for discovering scrape targets from the Outscale Cloud API - **added** — Emit a warning when sort, sort_by_label or sort_by_label_desc is used within range (matrix) queries - **added** — Add start(), end(), range(), and step() experimental functions to PromQL - **added** — Update resets() function to consider start timestamp resets, hidden behind use-start-timestamps feature flag - **added** — Add CheckpointFromInMemorySeries option to agent.DB that enables checkpoint based on in-memory series - **added** — Add a web interface for deleting time series and cleaning tombstones, accessible from the Status menu - **added** — Use start timestamps for rate(), irate(), and increase() calculations, behind a feature flag use-start-timestamps - **added** — Add feature flag st-synthesis which synthesizes unknown start timestamps for scraped cumulative metrics - **added** — Support @st annotation in load blocks to specify per-sample start timestamps in promqltest - **changed** — Promote auto-reload-config as stable - **changed** — Add Start Timestamp field to all WAL Histogram samples in memory when st-storage flag is enabled - **changed** — Add optional external_id field to AWS SD for ECS, MSK, RDS, and Elasticache - **changed** — Allow EC2 service discovery to discover IPv6 addresses to communicate with target endpoints - **changed** — Propagate SD target updates faster by introducing dynamic backoff interval instead of static 5s interval - **changed** — Add --header flag to promtool query instant command - **fixed** — Make head chunk lookup in range queries constant time instead of quadratic time This release contains security fixes, new features (especially around PromQL and Service Discovery), performance improvements in TSDB, Start Timestamp improvements and numerous bug fixes. Thanks to all contributors! ##### Key Highlights * **Security**: Two security vulnerabilities have been addressed: a denial of service in remote-write (snappy decompression limit) and a secret exposure leak in STACKIT service discovery. * **PromQL & Metadata**: Several features and bug fixes related to the experimental "start timestamps" support, including updates to `rate()`, `irate()`, `increase()`, and `resets()`. New experimental functions `start()`, `end()`, `range()`, and `step()` are introduced. * **TSDB Performance**: Optimizations in head chunk lookup (constant time) and mmap operations to reduce CPU usage. * **Service Discovery**: Added support for DigitalOcean Managed Databases and Outscale VM, along with improvements to AWS SD (IPv6 support for EC2, external ID support). * **UI**: Added a web interface for deleting time series and cleaning tombstones. ##### Changelog - [SECURITY] Remote: Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds the 32MB. Thanks to @hibrian827 for reporting it. #18642 - [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via `/-/config` endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18649 - [CHANGE] TSDB/Agent: Adds Start Timestamp field to all WAL Histogram samples in memory; used `st-storage` flag is enabled. #18221 - [FEATURE] API: Add `/api/v1/status/self_metrics` endpoint returning the current state of the Prometheus server's own metrics about itself as JSON. #18411 - [FEATURE] Discovery: Add DigitalOcean Managed Databases service discovery #18287 - [FEATURE] Prometheus: Add support for the aix/ppc64 compilation target #18321 - [FEATURE] Discovery: Add Outscale VM service discovery (`outscale_sd_configs`) for discovering scrape targets from the Outscale Cloud API. #18139 - [FEATURE] PromQL: Emit a warning when `sort`, `sort_by_label` or `sort_by_label_desc` is used within range (matrix) queries, as these functions do not have effect in that context. #18498 - [FEATURE] PromQL: Add `start()`, `end()`, `range()`, and `step()` experimental functions #17877 - [FEATURE] PromQL: Update `resets()` function to consider start timestamp resets. Hidden behind `use-start-timestamps` feature flag. #18627 - [FEATURE] Prometheus: Promote auto-reload-config as stable #18620 - [FEATURE] TSDB/Agent: Add `CheckpointFromInMemorySeries` option to `agent.DB` that enables checkpoint based on in-memory series. #17948 - [FEATURE] UI: Add a web interface for deleting time series and cleaning tombstones, accessible from the Status menu. #18390 - [FEATURE] PromQL: Use start timestamps for `rate()`, `irate()`, and `increase()` calculations, behind a feature flag `use-start-timestamps`. Doesn't work together with extended range selectors `anchored` and `smoothed`. #18344 - [FEATURE] Scrape: Added a feature flag `st-synthesis` which synthesizes unknown STs for scraped cumulative metrics. Useful when Remote Writing 2.0 with delta or Otel-based backends. #18279 - [FEATURE] promqltest: support `@st` annotation in `load` blocks to specify per-sample start timestamps. #18360 - [ENHANCEMENT] API: reject concurrent fgprof profiles. #18651 - [ENHANCEMENT] AWS SD: Add optional `external_id` field to ECS/MSK/RDS/Elasticache. #18579 - [ENHANCEMENT] AWS SD: Add optional `external_id` field. #17171 - [ENHANCEMENT] Discovery: Propagate SD target updates faster by introducing dynamic backoff interval instead of static 5s interval for throttling. #18187 - [ENHANCEMENT] Promtool: Add `--header` flag to `query instant` command, matching existing `query range` behaviour. #18418 - [ENHANCEMENT]: AWS SD: Allows EC2 service discovery to discover IPv6 addresses to communicate with target endpoints. The private IPv4 addr _[Truncated at 4000 characters — full notes: https://github.com/prometheus/prometheus/releases/tag/v3.12.0]_ ### v3.12.0-rc.0 — 3.12.0-rc.0 / 2026-05-19 - Date: 2026-05-19 - Version: v3.12.0-rc.0 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.12.0-rc.0 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.12.0-rc.0 - Labels: Pre-release - **security** — Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds 32MB - **security** — Fix secrets being exposed in plaintext via /-/config endpoint in STACKIT SD - **added** — Add /api/v1/status/self_metrics endpoint returning the current state of the Prometheus server's own metrics - **added** — Add DigitalOcean Managed Databases service discovery - **added** — Add support for the aix/ppc64 compilation target - **added** — Add Outscale VM service discovery (outscale_sd_configs) for discovering scrape targets from the Outscale Cloud API - **added** — Add start(), end(), range(), and step() experimental functions to PromQL - **added** — Add web interface for deleting time series and cleaning tombstones, accessible from the Status menu - **added** — Add feature flag st-synthesis which synthesizes unknown STs for scraped cumulative metrics - **changed** — Add Start Timestamp field to all WAL Histogram samples in memory when st-storage flag is enabled - **changed** — Update resets() function to consider start timestamp resets, hidden behind use-start-timestamps feature flag - **changed** — Use start timestamps for rate(), irate(), and increase() calculations, behind feature flag use-start-timestamps - **changed** — Promote auto-reload-config as stable - **changed** — Update rate(), irate(), increase(), and resets() functions for experimental start timestamps support - **added** — Add optional external_id field to AWS SD ECS/MSK/RDS/Elasticache - **added** — Allow EC2 service discovery to discover IPv6 addresses to communicate with target endpoints - **added** — Add --header flag to promtool query instant command - **changed** — Emit warning when sort, sort_by_label or sort_by_label_desc is used within range (matrix) queries - **fixed** — Fix info() function incorrectly handling negated __name__ matchers - **fixed** — Fix smoothed rate/increase returning zero instead of no result when all data falls strictly after the query range This release contains security fixes, new features (especially around PromQL and Service Discovery), performance improvements in TSDB, Start Timestamp improvements and numerous bug fixes. Thanks to all contributors! ##### Key Highlights * **Security**: Two security vulnerabilities have been addressed: a denial of service in remote-write (snappy decompression limit) and a secret exposure leak in STACKIT service discovery. * **PromQL & Metadata**: Several features and bug fixes related to the experimental "start timestamps" support, including updates to `rate()`, `irate()`, `increase()`, and `resets()`. New experimental functions `start()`, `end()`, `range()`, and `step()` are introduced. * **TSDB Performance**: Optimizations in head chunk lookup (constant time) and mmap operations to reduce CPU usage. * **Service Discovery**: Added support for DigitalOcean Managed Databases and Outscale VM, along with improvements to AWS SD (IPv6 support for EC2, external ID support). * **UI**: Added a web interface for deleting time series and cleaning tombstones. ##### Changelog - [SECURITY] Remote: Reject snappy-compressed received requests via Remote Write whose declared decoded length exceeds the 32MB. Thanks to @hibrian827 for reporting it. #18642 - [SECURITY] STACKIT SD: Fix secrets being exposed in plaintext via `/-/config` endpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18649 - [CHANGE] TSDB/Agent: Adds Start Timestamp field to all WAL Histogram samples in memory; used `st-storage` flag is enabled. #18221 - [FEATURE] API: Add `/api/v1/status/self_metrics` endpoint returning the current state of the Prometheus server's own metrics about itself as JSON. #18411 - [FEATURE] Discovery: Add DigitalOcean Managed Databases service discovery #18287 - [FEATURE] Prometheus: Add support for the aix/ppc64 compilation target #18321 - [FEATURE] Discovery: Add Outscale VM service discovery (`outscale_sd_configs`) for discovering scrape targets from the Outscale Cloud API. #18139 - [FEATURE] PromQL: Emit a warning when `sort`, `sort_by_label` or `sort_by_label_desc` is used within range (matrix) queries, as these functions do not have effect in that context. #18498 - [FEATURE] PromQL: Add `start()`, `end()`, `range()`, and `step()` experimental functions #17877 - [FEATURE] PromQL: Update `resets()` function to consider start timestamp resets. Hidden behind `use-start-timestamps` feature flag. #18627 - [FEATURE] Prometheus: Promote auto-reload-config as stable #18620 - [FEATURE] TSDB/Agent: Add `CheckpointFromInMemorySeries` option to `agent.DB` that enables checkpoint based on in-memory series. #17948 - [FEATURE] UI: Add a web interface for deleting time series and cleaning tombstones, accessible from the Status menu. #18390 - [FEATURE] PromQL: Use start timestamps for `rate()`, `irate()`, and `increase()` calculations, behind a feature flag `use-start-timestamps`. Doesn't work together with extended range selectors `anchored` and `smoothed`. #18344 - [FEATURE] Scrape: Added a feature flag `st-synthesis` which synthesizes unknown STs for scraped cumulative metrics. Useful when Remote Writing 2.0 with delta or Otel-based backends. #18279 - [FEATURE] promqltest: support `@st` annotation in `load` blocks to specify per-sample start timestamps. #18360 - [ENHANCEMENT] API: reject concurrent fgprof profiles. #18651 - [ENHANCEMENT] AWS SD: Add optional `external_id` field to ECS/MSK/RDS/Elasticache. #18579 - [ENHANCEMENT] AWS SD: Add optional `external_id` field. #17171 - [ENHANCEMENT] Discovery: Propagate SD target updates faster by introducing dynamic backoff interval instead of static 5s interval for throttling. #18187 - [ENHANCEMENT] Promtool: Add `--header` flag to `query instant` command, matching existing `query range` behaviour. #18418 - [ENHANCEMENT]: AWS SD: Allows EC2 service discovery to discover IPv6 addresses to communicate with target endpoints. The private IPv4 addr _[Truncated at 4000 characters — full notes: https://github.com/prometheus/prometheus/releases/tag/v3.12.0-rc.0]_ ### v3.11.3 — 3.11.3 / 2026-04-27 - Date: 2026-04-27 - Version: v3.11.3 - Original notes: https://github.com/prometheus/prometheus/releases/tag/v3.11.3 - Permalink: https://whatsnew.fyi/product/prometheus/releases/v3.11.3 - **security** — Fix OAuth client_secret being exposed in plaintext via /-/config endpoint in AzureAD remote write - **security** — Reject snappy-compressed requests in remote-read whose declared decoded length exceeds the decode limit - **security** — Fix stored XSS via unescaped le label values in old UI heatmap chart tick labels This release fixes mutiple security issues. We would like to thank the following people for the responsible disclosures: - Shadowbyte (4c1dr3aper) - Charlie Lewis for the Remote-Read snappy decode vulnerability. - Brett Gervasoni for the AzureAD OAuth `client_secret` vulnerability. - @iiihaiii and @Ngocnn97 for the Old UI XSS vulnerability. - [SECURITY] AzureAD remote write: Fix OAuth `client_secret` being exposed in plaintext via `/-/config` endpoint. GHSA-wg65-39gg-5wfj / CVE-2026-42151 #18590 - [SECURITY] Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. GHSA-8rm2-7qqf-34qm / CVE-2026-42154 #18584 - [SECURITY] UI: Fix stored XSS via unescaped `le` label values in old UI heatmap chart tick labels. GHSA-fw8g-cg8f-9j28 #18588