Intel

AIKIDO-2025-10022

github.com/prometheus/alertmanager is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 16, 2025

30

Low Risk

This Affects:

gogithub.com/prometheus/alertmanager
0.5.0 - 0.27.0
Fixed in 0.28.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a race condition in the dispatch.go module that creates a vulnerability that may lead to improper deletion of alerts during notification cleanup. It can allow attackers to suppress critical alerts, compromising timely incident detection and response.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/prometheus/alertmanager is vulnerable to Race Condition in versions 0.5.0 - 0.27.0.

How to fix this

Upgrade the github.com/prometheus/alertmanager library to the patch version.