Fleet Unauthenticated Denial-of-Service Vulnerability via Unbounded Request Body Read

Vulnerability

A denial-of-service vulnerability has been identified in Fleet device management software, affecting versions prior to 4.81.0. The issue arises from multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. This lack of restriction allows an unauthenticated attacker to send large or repeated HTTP payloads, causing excessive memory allocation and leading to a denial-of-service condition by exhausting available memory and forcing the Fleet server process to restart.

Impact

Exploitation of this vulnerability causes the Fleet server process to run out of available memory and restart, disrupting service availability.

Remediation

Users can upgrade to Fleet version 4.81.0 or later to address this vulnerability. If an immediate upgrade is not possible, request body size limits can be applied at a reverse proxy or load balancer, such as NGINX or Envoy. Additionally, network access to the affected endpoints can be restricted to known IP ranges where feasible, and memory usage and restart frequency can be monitored for abnormal patterns.

Added: Mar 27, 2026, 7:28 PM
Updated: Mar 27, 2026, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
8.1
remediation
7.9
relevance
4.8
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.