Home

Description

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending large or repeated HTTP payloads, causing excessive memory allocation and resulting in a denial-of-service (DoS) condition. Version 4.81.0 patches the issue.

PUBLISHED Reserved 2026-02-10 | Published 2026-03-27 | Updated 2026-03-31 | Assigner GitHub_M




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 4.81.0
affected

References

github.com/.../fleet/security/advisories/GHSA-99hj-44vg-hfcp

cve.org (CVE-2026-26061)

nvd.nist.gov (CVE-2026-26061)

Download JSON