PT-2026-28347 · Envoy+2 · Envoy+2

Fuzzztf

·

Published

2026-03-27

·

Updated

2026-04-07

·

CVE-2026-26061

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.0
Description Fleet, an open source device management software, has multiple unauthenticated HTTP endpoints that do not enforce a size limit when reading request bodies. An unauthenticated attacker can exploit this by sending large or repeated HTTP payloads, leading to excessive memory allocation and a denial-of-service (DoS) condition. The issue impacts availability only, with no exposure of sensitive data, authentication bypass, privilege escalation, or integrity impact.
Recommendations Versions prior to 4.81.0 should be upgraded to version 4.81.0 or later. As a temporary workaround, apply request body size limits at a reverse proxy or load balancer (e.g., NGINX, Envoy). Restrict network access to the endpoints to known IP ranges where feasible. Monitor memory usage and restart frequency for abnormal patterns.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2026-26061
GHSA-99HJ-44VG-HFCP
GO-2026-4889
SUSE-SU-2026:1205-1

Affected Products

Envoy
Fleet
Nginx