Last 7 days
1
Features: 0
Changes: 0
Fixes: 0
Deprecations: 1
Metrics monitoring and alerting toolkit for cloud-native systems.
Latest Prometheus changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Prometheus release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
1
2
7
24
Deprecate non‑true/all values for the stats query parameter on /api/v1/query and /api/v1/query_range, now returning a warning and slated for removal in the next major release.
Updated golang.org/x/text to v0.39.0 and google.golang.org/grpc to v1.82.1, fixing CVE‑2026‑56852 and GHSA‑hrxh‑6v49‑42gf.
Fixed TSDB head chunk cache returning samples from the wrong chunk after truncation.
Updated build to Go 1.25.12.
Fixed a critical XSS issue in the UI and stopped forwarding credentials on cross‑host redirects, tightening security.
Fixed multiple security issues, including plaintext secret exposure via the /config endpoint and updated Go and UI dependencies to patched versions addressing several CVEs
- Fixed two security issues: a remote‑write denial‑of‑service via oversized snappy payloads and a secret‑exposure leak in STACKIT service discovery.
Fixes multiple security vulnerabilities: AzureAD OAuth client secret exposure via /config endpoint.
Fix AzureAD OAuth client secret exposure via the /config endpoint (CVE-2026-42151).
Fix stored XSS vulnerability in Prometheus UI tooltips and metrics explorer (CVE‑2026‑40179).
Fixed stored XSS vulnerability in UI tooltips and metrics explorer (CVE‑2026‑40179)
Fix startup failure for OTLP HTTP tracing when the insecure flag is set to true
Added multiple new service-discovery roles (AWS Elasticache & RDS, Azure Workload Identity, Kubernetes node‑role selectors and pod‑label enrichments) and introduced new PromQL histogram operators and experimental TSDB flags for start tim...
Added a distroless Docker image variant (non‑root UID/GID 65532, no VOLUME) alongside the default busybox image, improving container security.
LTS release with no functional changes since 3.5.0
Fixed Agent crash on startup caused by invalid object type.
Native Histograms are now GA – the experimental flag is removed and collection is enabled via the new `scrape_native_histograms` config option (breaking change for flag users).
Fix Remote Write receiver to send correct response headers for v1 flow
Native histograms are now a stable, optional feature; enable via the new `scrape_native_histograms` setting (default false) and transition using the existing feature flag.
Reverted the breaking redirect behavior for web.external URLs when a web.route prefix is set.
Fix AWS SDK v2 credentials handling for EC2 and Lightsail discovery.
Fix OTLP label translation by prefixing keys for attributes that start with a single underscore
Breaking change: OTLP endpoint no longer auto‑translates underscore‑prefixed attribute names; use version 3.7.1 for ingestion.
Added PromQL step(), min() and max() on durations, stricter NaN handling, and multiple histogram fixes with performance optimizations.
Added experimental type/unit metadata labels and new PromQL functions for time series aggregation, plus OTLP config options and STACKIT Cloud discovery
Added backward compatibility for the upcoming TSDB block index v3.
Fix default OTLP receiver configuration when otlp block is missing
Add reproducer for a dangling reference issue in parsers
Added OTLP translation and ingest features (native histogram flag, optional name/attribute translation, delta metrics support) and PromQL enhancements (arithmetic in durations, histogram fraction, corrected stddev/stdvar calculations).
Fix panic in Azure Service Discovery when encountering malformed log messages
Add PromQL idelta() and irate() functions for native histograms
Fixed runtime bug where GOGC was set to 0 with an empty prometheus.yml, preventing high CPU usage.
Fixed issue where an `Accept` header with `escape=allow utf8` was sent even when the metric name validation scheme was set to `legacy`.
Added OTLP delta‑to‑cumulative conversion flag and enabled UTF‑8 characters in relabel target labels and rule names.
Security: upgraded golang.org/x/crypto to patch CVE‑2024‑45337.
Fix PromQL subqueries to remain open
Brand‑new web UI replaces the old UI and UTF‑8 support is enabled by default, removing the related feature flags.
Fix bug where round() function retained the name label after rounding
Fix scraping to allow multiple samples on the same series with explicit timestamps
Add experimental PromQL info function, support UTF‑8 label names, and enable custom HTTP headers in scraping configs.
Scraping now allows multiple samples on the same series with explicit timestamps.
Fixed a segmentation fault crash in Prometheus when a remote read accessed a block concurrently with TSDB block creation.
Introduce experimental Remote Write v2 (enabled by default, configurable via feature flag) with new metadata WAL support and future‑timestamp rejection
Revert change from v2.51.0 that caused remote write to drop samples during prolonged flow stalls
Patched vulnerable dependencies with security updates
Change Go runtime GOGC default from 100 to 75, reducing memory usage while keeping CPU impact low
Added new features: Kubernetes SD failure metric and node/zone metadata, Azure authorization SDK support, native histogram templating for alerting, IPv6 range discovery in Linode SD, and several PromQL/TSDB performance improvements.
Fixed TSDB agent bug where new series were not written to the WAL during a rollback
Fixed a hang in the Notifier when relabeling alerts.
Reinstates validation for label join destination label in PromQL
Added native histogram support across UI, PromQL (avg function), and latency metrics, plus relabel rules for AlertManagerConfig routing.
Fixed remote read bug by releasing querier resources before encoding results.
Fixes broken /metadata API caused by incorrect field names.
Added multiple new features: Remote Write can drop old in‑memory samples and returns HTTP 400 for too‑old samples; experimental zero‑timestamp ingestion; overlapping compaction, automatic memory‑limit handling, and a new promtool "analyz...
Updated build to Go 1.21.6 with security patches for dependencies.
Fixed incorrect q= parameter in TSDB scrape Accept header.
Added numerous new features: promtool run flag, DNS SD NS records, UI heatmap setting, configurable gzip compression, experimental PromQL functions, scrape protocol priority, file‑based basic auth for HTTP clients, and an alerts exclusio...
Updated build to Go 1.21.5
Fix TSDB wlog watcher to read segments synchronously when not tailing.
Add AWS SigV4 auth for Alertmanager endpoints and Azure AD OAuth for remote write requests.
Fixed TSDB counter reset edge cases causing native histogram panics.
Fixed duplicate sample detection at the chunk size limit (12874).
Add support for larger Hetzner SD IDs, preparing for upcoming changes.
Add experimental OpenTelemetry (OTLP) ingestion endpoint.
Update the Go toolchain to the latest version
Promtool now supports PromQL formatting, label matcher set/delete commands, a push metrics command, and reads from stdin when no files are given for rule checks.
Added new features: API limit parameter, global config limits, Consul path‑prefix support, native histogram operators and dual‑format scraping, Azure AD remote write, configurable TSDB samples per chunk, and Promtool block analysis.
Remote write default samples per send raised to 2,000 and remote read now supports native histograms.
Update Go toolchain to latest version
Introduces a special build using the stringlabels Go tag that replaces label/value storage with a single string
Fixed Labels Set() after Del() being ignored, which broke certain relabeling rules.
Fix Prometheus target scrape pool limit metric not set before reload
Introduced optional “stringlabels” build/tag and Docker image for reduced heap usage and speed improvements in label handling.
Introduces a stringlabels build that stores labels as a single string, reducing heap usage
Updated the toolchain to be built on Go 1.19.
Changed WAL record format for experimental native histograms, breaking compatibility – upgrade requires removing the WAL directory to avoid data loss.
Added new relabel actions (keepequal, dropequal) and HTTP proxy header support
Fixed DNS resolution on Windows by using the native resolver.
Updated Go runtime and upstream dependencies
Upgraded Go runtime and upstream dependencies to versions with security fixes.
Fix TSDB queries involving native histograms by correcting iterator reset logic.
Fix basic authentication bypass vulnerability (CVE‑2022‑46146).
Fix basic authentication bypass vulnerability (CVE‑2022‑46146).
Fixed TSDB compaction failure that occurred after a deletion was called.
Update regexp library to address CVE‑2022‑41715.
Correct metric name text color in dark mode UI
Fix alignment for atomic int64 on 32-bit architectures in TSDB.
Fixed atomic int64 alignment issue on 32‑bit architectures in TSDB.
Introduce experimental native histogram support with a flag and switch default exposition to protobuf
Fix TSDB startup error caused by invalid magic number in Prometheus.
Fixed bug where notifier relabel incorrectly modified labels on active alerts.
Add experimental TSDB support for ingesting out‑of‑order samples via a configurable time window.
Close file descriptor correctly when logging unfinished queries
Added /api/v1/format endpoint and UI support for pretty‑formatting PromQL, plus a toTime() template function and DNS SD MX record discovery.
Add new Nomad service discovery integration
Fix static asset serving (fonts, favicon).
Promtool now includes a "lint fatal" option that can treat lint warnings as errors.
Added new relabel actions (lowercase/uppercase) and service discovery integrations for IONOS Cloud and Vultr, plus a Linode failure‑count metric.
TLS defaults hardened: TLS 1.0/1.1 disabled client‑side, SHA‑1 certificates rejected (except self‑signed roots).
Removed Classic UI (breaking) and switched tracing from Jaeger to OpenTelemetry.
Binaries built with Go 1.17.8 to mitigate CVE‑2022‑24921.
Fix panic in TSDB when mapping head chunks onto the disk.
- Fixed regression in Azure SD where operations failed when the public IP address was not set.
Fix panic in Azure SD when IP address is missing.
Resolve SD error "no such file or directory" when Kubernetes service discovery runs outside a cluster
PromQL negative offset and @ modifier, plus remote‑write receiver, promoted to stable features.
Fixed metrics reporting when sample limit is reached during scraping
Introduce Prometheus Agent mode for remote‑write‑only operation, enabled via `--enable-feature=agent`.
Fixed TSDB query failures that occurred after a snapshot replay error
Fixed TSDB query handling after a failed snapshot replay
Fix panic in experimental discovery manager when receiving targets during a reload
Replace the standard PromQL editor with a CodeMirror‑based one and add trigonometric functions, atan2 operator, and exemplar support in remote write.
Fixed panic occurring during failed TSDB snapshot replay.
Prevent TSDB from erroring on overlapping mmap chunks during WAL replay
Redact remote write URLs in metric labels and hide passwords for remote write and proxy URLs on the config UI.
Added experimental TSDB memory snapshot on shutdown and configurable scrape intervals/timeout via relabeling, plus new scrape timeout and sample limit metrics.
Fixed Kubernetes service discovery failing to discover Ingress on Kubernetes v1.22.
Fixed panic on 32‑bit architectures by aligning atomically accessed int64 values in tsdb.
Promoted storage.tsdb.allow-overlapping-blocks and storage.tsdb.retention.size flags to stable; added Kuma service discovery, present_over_time PromQL function, and configurable exemplar storage with reload support
Allow charset specification in HTTP Service Discovery Content-Type header
Made the experimental PromQL editor the default UI, added exemplar display and a startup progress screen.
Fixed security vulnerability (CVE-2021-29622) allowing arbitrary redirects via the /new API endpoint.
Fixes an arbitrary redirect vulnerability on the /new API endpoint (CVE‑2021‑29622).
Added new discovery integrations (AWS Lightsail, Docker, DigitalOcean VPC label, Scaleway secret file), OAuth 2.0 support, a dark UI theme, and experimental remote write exemplar sending.
Updated Prometheus to build with Go 1.16, improve RSS memory metrics, and switch default Alertmanager to v2 API.
Fix ingestion of scrapes when the wall clock changes, such as after system suspend.
Fix crash in promtool when a subquery with default resolution is used.
Added an `enable feature=` flag exposing experimental capabilities: remote‑write receiver API and PromQL “@ <timestamp>” modifier.
Cache basic authentication results to boost HTTP endpoint performance.
Added TLS and basic auth to HTTP endpoints and new promtool subcommands for web config checks and OpenMetrics block creation.
- UI: React UI set as the default and button display bug fixed.
Fixed race condition in scraper synchronization, stopping, and reloading.
Fix potential "mmap: invalid argument" errors when loading head chunks after unclean shutdown by adding read repairs
Removed the experimental gRPC API v2, breaking the APIv2 endpoint.
Built with Go 1.15, deprecating X.509 CommonName validation and announcing removal of the experimental gRPC API v2 in the next minor release.
Reduced Consul watch timeout to 2 minutes and aligned the request timeout accordingly
Prevent panic on TSDB WAL corruption
Enabled TSDB WAL compression by default, making downgrade to v2.10 or earlier require the explicit no‑storage.tsdb.wal‑compression flag (breaking change).
Fix panic in Remote Write when reloading config with modified queue parameters
Fix TSDB map file truncation that caused non‑sequential files.
Added memory‑mapped TSDB head block, reducing memory usage and speeding restarts (feature, always enabled).
Corrected TSDB query handling to return accurate results when Prometheus remote reads are configured.
Fixed TSDB snapshot API to correctly handle snapshot requests
Added experimental Jaeger tracing support.
Fix federation metrics registration issue
Fix TSDB query performance regression that caused elevated memory and CPU usage
Added TSDB isolation to guarantee queries and recording rules see only full scrapes, with increased memory/CPU/latency overhead.
Added local timezone support in graph UI, new absent_over_time PromQL function, and optional per‑query logging.
Fixed support for TSDB blocks built with Prometheus before 2.1.0.
Fix race condition when multiple concurrent queries access the same data
Added a new /metadata API endpoint and enhanced remote read/write (query grouping, range hints, per‑queue bytes counter, and label renaming).
Added new API endpoints (/api/v1/status/runtimeinfo, /api/v1/status/buildinfo) and introduced an experimental React‑based UI with cardinality stats on the status page.
Fix panic in ARM builds of Prometheus
Fixed stored DOM XSS vulnerability in UI (CVE‑2019‑10215).
Added ability to log active PromQL queries and released binaries for mips64/mips64le architectures.
Updated Bootstrap3 typeahead component to version 4.0.2 in the web UI
Fix potential panic when Prometheus watches multiple Zookeeper paths
Added support for Alertmanager API v2, InitContainers in Kubernetes service discovery, and optional Snappy compression of WAL records.
Introduced new observability features: external labels in templates, $rawParams/$params/$path variables, a metric for the TSDB WAL segment, and a scrape‑series‑added metric.
Fix subquery range handling for selection queries
Fixed missing label sanitization in Discovery/kubernetes
Upgrade to Go 1.12 changes memory release behavior, leading to higher RSS numbers (harmless).
Restore display of job labels in the /targets endpoint
Introduced optional experimental support for overlapping TSDB blocks and switched remote write API to use Write Ahead Logging (WAL).
Fixed Prometheus rule group last evaluation timestamp to use Unix timestamp seconds.
Fix a Stored DOM XSS vulnerability in the query history feature (security).
Rollback Dockerfile to version 2.5.0, undoing the breaking change from 2.6.0 and deprecate the storage.tsdb.retention flag in favor of storage.tsdb.retention.time (warning emitted).
Fix Azure service discovery getting stuck intermittently.
Added JSON log format flag, new /api/v1/labels endpoint, and customizable web UI title via flags.
Added experimental OpenMetrics support and made query sample limits and remote read concurrency configurable (feature).
Fix panic when using custom EC2 API (SD‑4672)
Fix handling of WAL corruption cases in the tsdb component.
Introduced new TSDB metrics for Prometheus (TSDB integration).
Introduced a new WAL implementation that breaks forward compatibility and added APIs for per‑target metric metadata, rule management, and persistent alert state
Fixed multiple TSDB issues: error propagation, timeout handling, and race conditions.
- Fixed infinite loop with duplicate NaN values and nil‑pointer dereference in API endpoints.
Added token‑based authentication for Marathon service discovery with support for basic/bearer auth and file‑based password configuration.
Fix data loss in TSDB during compaction
Improved storage format makes downgrades impossible (breaking change).
Added new Service Discovery UI and Admin APIs (delete, snapshot, tombstones) plus UI enhancements like graph autocomplete and faster federation.
Completely rewritten storage layer with WAL, breaking compatibility with 1.x and altering many flags
Fix EC2 service discovery to handle empty tag lists gracefully