Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions sources/metadata/pmm-server/3.8.1.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
version: 3.8.1
imageInfo:
image_path: "perconalab/pmm-server:3-dev-latest"
image_hash: "sha256:eb2f1aa9c44a76347f2bf011e21a1264e9ab8a76d8d625b7e6995a62e0e169fa"
image_release_timestamp: "2026-05-22T9:01:02.343594Z"
image_path: "perconalab/pmm-server:3.8.1-rc"
image_hash: "sha256:ef47471fb3b54e10897a92bab0b7b45e82d9825c3b0abf5a0693242191f99468"
image_release_timestamp: "2026-06-16T13:47:01.085828074Z"
status: "available"
6 changes: 6 additions & 0 deletions sources/metadata/pmm-server/3.9.0.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
version: 3.9.0
imageInfo:
image_path: "perconalab/pmm-server:3-dev-latest"
image_hash: "sha256:ca7ff57b088f93836d9214bcc2726164fc16340387e7faa819c8bea0d7e9affc"
image_release_timestamp: "2026-06-09T10:09:45.632195753Z"
status: "available"
150 changes: 148 additions & 2 deletions sources/release-notes/pmm/3.8.1.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,149 @@
## Release summary
## 📋 Release summary

Here goes 3.8.1 release summary and release notes...
PMM 3.8.1 is a security-focused release that patches critical and high-severity vulnerabilities in gRPC, Grafana, and nginx, and fixes several ClickHouse and dashboard stability issues.

## 🔒 Security updates

### Fixed since PMM 3.8.0

- **[CVE-2026-33816](https://nvd.nist.gov/vuln/detail/CVE-2026-33816) (CRITICAL) -- pgx memory-safety vulnerability.** Resolved by bumping pgx from v5.8.0 to v5.9.2 in the Percona Grafana fork.
- **[CVE-2026-33186](https://nvd.nist.gov/vuln/detail/CVE-2026-33186) (HIGH) -- gRPC authorization bypass.** Resolved through upstream dependency updates across PMM components.
- **[CVE-2026-42504](https://nvd.nist.gov/vuln/detail/CVE-2026-42504) (HIGH) -- Go stdlib MIME header decoding DoS.** Resolved across pmm-dump, VictoriaMetrics, and vmalert by rebuilding on Go 1.26.4.
- **[CVE-2026-41567](https://nvd.nist.gov/vuln/detail/CVE-2026-41567), [CVE-2026-42306](https://nvd.nist.gov/vuln/detail/CVE-2026-42306) (HIGH) -- Docker engine vulnerabilities in Nomad.** Resolved through upstream Nomad dependency update.
- **[CVE-2026-1642](https://nvd.nist.gov/vuln/detail/CVE-2026-1642) (HIGH) -- nginx TLS backend injection.** Resolved by upgrading the bundled nginx.

All PMM-owned binaries (pmm-managed, pmm-agent, pmm-admin, all exporters, VictoriaMetrics, vmalert, vmproxy, qan-api2, pmm-dump, Nomad) report zero known vulnerabilities.

### Grafana upgraded to 12.4.3+security-02

PMM 3.8.1 upgrades Grafana to 12.4.3+security-02 to address 10 security vulnerabilities. We recommend upgrading to PMM 3.8.1 as soon as possible. For the full list of CVEs addressed through this upgrade, see the [Grafana 12.4.3+security-02 release notes](https://github.com/grafana/grafana/releases/tag/v12.4.3%2Bsecurity-02).

### Residual security risk

As part of modern software development, complex systems commonly rely on third-party components, and some level of residual risk may remain at release time despite ongoing vulnerability management efforts. This is particularly the case when vulnerabilities in upstream dependencies are disclosed close to, or coincident with, a planned release.

The following CVEs remain present in third-party dependencies included with PMM. After assessment, the residual risk to PMM deployments is considered low due to limited exploitability, existing architectural boundaries, and available mitigating controls.

We will continue to monitor upstream disclosures and newly identified vulnerabilities, reassess their impact on PMM, and take appropriate remediation actions in future releases.

### Go JOSE denial of service -- [CVE-2026-34986](https://nvd.nist.gov/vuln/detail/CVE-2026-34986)

**Affected component** Grafana binary (go-jose v4.1.3, fixed in v4.1.4).

**Risk assessment** Denial of service via crafted JSON Web Encryption objects. In PMM, Grafana uses go-jose for JWT/JWE processing in authentication workflows. Exploitation requires sending crafted JWE tokens to Grafana's authentication endpoints.

**Mitigating factors**

- PMM authentication is required to access Grafana.
- The impact is limited to denial of service, not data access or code execution.

**Risk decision** Low risk in PMM. Residual risk accepted for PMM 3.8.1. Will be resolved through a Grafana upstream update in a future release.

### Docker engine vulnerabilities in Grafana transitive dependencies -- [CVE-2026-34040](https://nvd.nist.gov/vuln/detail/CVE-2026-34040), [CVE-2026-41567](https://nvd.nist.gov/vuln/detail/CVE-2026-41567) & [CVE-2026-42306](https://nvd.nist.gov/vuln/detail/CVE-2026-42306)

**Affected component** Grafana binary (`moby/moby` as a transitive build dependency).

**Risk assessment** These are Docker engine vulnerabilities (authorization bypass, container archive execution on host, `docker cp` race condition). PMM does not run or expose a Docker daemon. The `moby/moby` library is compiled into Grafana as a build dependency -- the vulnerable code paths are never executed in a PMM deployment.

**Mitigating factors**

- PMM Server does not run a Docker daemon or expose Docker API endpoints.
- These code paths exist only as unused transitive dependencies in the Grafana binary.
- No PMM operation invokes Docker container management functions.

**Risk decision** Not exploitable in PMM. Residual risk accepted for PMM 3.8.1.

### Grafana Tempo denial of service and information disclosure -- [CVE-2026-21728](https://nvd.nist.gov/vuln/detail/CVE-2026-21728) & [CVE-2026-28377](https://nvd.nist.gov/vuln/detail/CVE-2026-28377)

**Affected component** Grafana binary (Tempo is compiled into Grafana as an optional datasource plugin).

**Risk assessment** Tempo is a distributed tracing backend. PMM does not use Tempo, does not configure a Tempo datasource, and does not accept tracing data. The denial of service via large queries and S3 encryption key disclosure via status endpoint cannot be triggered in a PMM deployment.

**Mitigating factors**

- PMM does not configure or enable the Tempo datasource.
- No PMM component sends or receives tracing data through Tempo.
- The vulnerable endpoints are not exposed in PMM's Grafana configuration.

**Risk decision** Not exploitable in PMM. Residual risk accepted for PMM 3.8.1.

### Apache Thrift integer overflow -- [CVE-2026-41602](https://nvd.nist.gov/vuln/detail/CVE-2026-41602)

**Affected component** Grafana binary (Thrift is a transitive dependency).

**Risk assessment** Integer overflow in `TFramedTransport`. PMM does not use Thrift-based protocols for any inter-component communication. The vulnerable code path is not reachable through any PMM operation.

**Mitigating factors**

- PMM uses gRPC and HTTP/JSON for all inter-component communication, not Thrift.
- The Thrift library is an unused transitive dependency in the Grafana binary.

**Risk decision** Not exploitable in PMM. Residual risk accepted for PMM 3.8.1.

### Prometheus library vulnerabilities -- [CVE-2026-42151](https://nvd.nist.gov/vuln/detail/CVE-2026-42151) & [CVE-2026-42154](https://nvd.nist.gov/vuln/detail/CVE-2026-42154)

**Affected component** Grafana binary (embeds Prometheus library `v0.303.1` for query evaluation).

**Risk assessment** PMM uses VictoriaMetrics as its metrics backend, not Prometheus. However, Grafana's Prometheus datasource query path uses this library for PromQL evaluation. CVE-2026-42151 is an information disclosure of Azure OAuth client secrets via the config API -- PMM does not use Azure OAuth for Prometheus. CVE-2026-42154 is a denial of service via uncontrolled memory allocation in remote read -- exploitation would require an authenticated PMM user to craft specific queries through the Grafana interface.

**Mitigating factors**

- PMM authentication is required to access Grafana and execute queries.
- PMM does not use Azure OAuth or Prometheus remote read.

**Risk decision** Residual risk accepted for PMM 3.8.1.

### OpenTelemetry vulnerabilities -- [CVE-2026-29181](https://nvd.nist.gov/vuln/detail/CVE-2026-29181), [CVE-2026-24051](https://nvd.nist.gov/vuln/detail/CVE-2026-24051) & [CVE-2026-39883](https://nvd.nist.gov/vuln/detail/CVE-2026-39883)

**Affected component** Grafana binary (OpenTelemetry SDK `v1.39.0`).

**Risk assessment** CVE-2026-24051 and CVE-2026-39883 are PATH hijacking vulnerabilities requiring local shell access to the PMM Server container and the ability to modify `$PATH`. CVE-2026-29181 is a denial of service via crafted OpenTelemetry baggage headers, which requires untrusted OpenTelemetry traffic reaching Grafana.

**Mitigating factors**

- PMM Server containers run as non-root with restricted filesystem access.
- PMM does not accept inbound OpenTelemetry traffic.
- PATH hijacking requires pre-existing container compromise, which exceeds the PMM threat model.

**Risk decision** Not exploitable in PMM. Residual risk accepted for PMM 3.8.1.

### Go standard library vulnerabilities in ClickHouse datasource -- [CVE-2026-25679](https://nvd.nist.gov/vuln/detail/CVE-2026-25679), [CVE-2026-27137](https://nvd.nist.gov/vuln/detail/CVE-2026-27137), [CVE-2026-32280](https://nvd.nist.gov/vuln/detail/CVE-2026-32280), [CVE-2026-32281](https://nvd.nist.gov/vuln/detail/CVE-2026-32281), [CVE-2026-32283](https://nvd.nist.gov/vuln/detail/CVE-2026-32283), [CVE-2026-33810](https://nvd.nist.gov/vuln/detail/CVE-2026-33810), [CVE-2026-33811](https://nvd.nist.gov/vuln/detail/CVE-2026-33811), [CVE-2026-33814](https://nvd.nist.gov/vuln/detail/CVE-2026-33814), [CVE-2026-39820](https://nvd.nist.gov/vuln/detail/CVE-2026-39820), [CVE-2026-39823](https://nvd.nist.gov/vuln/detail/CVE-2026-39823), [CVE-2026-39825](https://nvd.nist.gov/vuln/detail/CVE-2026-39825), [CVE-2026-39836](https://nvd.nist.gov/vuln/detail/CVE-2026-39836), [CVE-2026-42499](https://nvd.nist.gov/vuln/detail/CVE-2026-42499) & [CVE-2026-42504](https://nvd.nist.gov/vuln/detail/CVE-2026-42504)

**Affected component** Grafana ClickHouse Datasource plugin (third-party, not Percona-maintained). Built on Go 1.26.0; fixes require Go 1.26.4 or later.

**Risk assessment** These are Go standard library issues affecting crypto/x509, crypto/tls, net/url, net/http, net/mail, and MIME header processing. The ClickHouse datasource connects exclusively to PMM's internal ClickHouse instance over a trusted localhost connection. It does not process untrusted URLs, validate external TLS certificates, parse email addresses, decode MIME content, or act as a reverse proxy. CVE-2026-39836 (net.Dial NUL byte panic) affects Windows only and does not apply to PMM Server.

**Mitigating factors**

- The ClickHouse datasource connects only to PMM's internal ClickHouse instance on localhost.
- PMM Server runs on Linux; the Windows-specific CVE does not apply.
- No untrusted external input reaches the ClickHouse datasource query path without prior PMM authentication.
- The plugin does not use TLS, reverse proxying, email parsing, or MIME processing in PMM's deployment.

**Risk decision** Residual risk accepted for PMM 3.8.1. The upstream plugin requires a Go toolchain update. This will be resolved when a new upstream release is available.

### Customer guidance

To further reduce exposure, Percona recommends:

- Restricting network access to PMM Server to trusted networks and users.
- Minimising the number of PMM administrators and enforcing strong authentication.
- Applying resource limits to PMM Server containers where supported.

## ✅ Fixed issues

- [PMM-15054](https://perconadev.atlassian.net/browse/PMM-15054): Fixed an issue where ClickHouse system log tables grew out of control, consuming all available memory and causing PMM Server to fail with `MEMORY_LIMIT_EXCEEDED` errors. PMM now disables the log tables it no longer uses and cleans up leftover tables from previous upgrades.

- [PMM-14858](https://perconadev.atlassian.net/browse/PMM-14858): Fixed an issue where PMM logged repeated connection errors when configured to use an external ClickHouse instance instead of the built-in one.

- [PMM-14763](https://perconadev.atlassian.net/browse/PMM-14763): Fixed an issue where OS metrics for AWS RDS instances continued to show data from the old primary after a blue-green switchover, instead of switching to the new primary.

- [PMM-15075](https://perconadev.atlassian.net/browse/PMM-15075): Fixed an issue where the ClickHouse **Read Backoff** panel on the **PMM Health** dashboard displayed an error instead of the graph. Also standardized font sizes across all dashboard panels.

- [PMM-15051](https://perconadev.atlassian.net/browse/PMM-15051): Fixed an issue where updating the public address in **Settings > Advanced Settings** returned a server error.

- [PMM-14894](https://perconadev.atlassian.net/browse/PMM-14894): Fixed the **Cluster Messages** graph in the **Valkey/Redis Cluster Details** dashboard to show the number of cluster messages per second instead of a cumulative total. The graph legend is also restored.

- [PMM-15112](https://perconadev.atlassian.net/browse/PMM-15112): Fixed an issue where a leftover live reload script in Grafana caused an unexpected browser prompt for some users.

- [PMM-14901](https://perconadev.atlassian.net/browse/PMM-14901): Fixed an issue in Real-Time Analytics (RTA) where the arrow navigation in the query details pane ignored active filters, moving through all queries instead of only the filtered ones.
3 changes: 3 additions & 0 deletions sources/release-notes/pmm/3.9.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
## Release summary

Here goes 3.9.0 release summary and release notes...
Loading