The Prometheus security policy, including how to report vulnerabilities, can be found here:
Security: prometheus/client_golang
Security
SECURITY.md
- 
  InstrumentHandler* HTTP middleware prone to DoS through method label cardinalityGHSA-cg3q-j54f-5p7p publishedFeb 15, 2022 by bwplotkaModerate
         Learn more about advisories related to prometheus/client_golang in the GitHub Advisory Database