
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26061 is a denial-of-service vulnerability in FleetDM Fleet caused by unbounded HTTP request body reads on multiple unauthenticated endpoints. An unauthenticated remote attacker can send oversized or repeated HTTP payloads to trigger excessive memory allocation, causing the Fleet server process to exhaust available memory and restart. All Fleet versions prior to 4.81.0 are affected. The vulnerability was disclosed on March 27, 2026, with a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Github Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): Fleet's HTTP server reads request bodies from multiple unauthenticated endpoints without enforcing any size limit, allowing an attacker to force unbounded memory allocation. Because no authentication is required and no size cap is enforced, an attacker can send arbitrarily large or repeated HTTP POST/PUT requests to these endpoints over the network with low complexity and no user interaction. The vulnerability was responsibly disclosed by researcher @fuzzztf (GitHub Advisory). No public proof-of-concept exploit code has been observed as of the time of this report (Feedly).
Successful exploitation results in a denial-of-service condition: the Fleet server process exhausts available memory and restarts, disrupting availability for all users and managed endpoints relying on the Fleet server. The impact is strictly limited to availability — there is no exposure of sensitive data, no authentication bypass, no privilege escalation, and no integrity impact (GitHub Advisory). In environments where Fleet is used for device management and security monitoring, repeated exploitation could cause sustained operational disruption and gaps in endpoint visibility.
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation as of the time of this report (Feedly). The EPSS score is approximately 0.051% (0.023% per GitHub Advisory), placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no special privileges, and no user interaction, making it trivially automatable if targeted (Github Advisory).
curl, wrk, or custom scripts to send a high volume of large HTTP requests to the vulnerable endpoints, forcing the server to allocate memory for each request body without releasing it promptly.Content-Length headers or chunked transfer encoding from a single or small set of source IPs; error log entries indicating out-of-memory conditions or process restarts.top, htop, Prometheus metrics); unexpected Fleet server process restarts or crash dumps.Upgrade Fleet to version 4.81.0 or later, which enforces request body size limits on affected endpoints (GitHub Advisory). If immediate upgrading is not possible, apply the following mitigations: configure request body size limits at a reverse proxy or load balancer (e.g., client_max_body_size in NGINX or equivalent in Envoy); restrict network access to Fleet endpoints to known, trusted IP ranges; and monitor Fleet server memory usage and restart frequency for anomalous patterns. Contacting Fleet's security team at security@fleetdm.com is recommended for additional guidance (Github Advisory).
The vulnerability was responsibly disclosed by researcher @fuzzztf and remediated by MagnusHJensen as the remediation developer, with the advisory published by lukeheath on behalf of FleetDM (GitHub Advisory). The CVE was picked up by standard vulnerability aggregators including VulnDB, CIRCL, and ENISA's EUVD shortly after disclosure, with no notable broader media coverage or significant social media discussion identified beyond automated CVE notification channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."