Sploitus

CVE-2026-26061

No indexed exploits for CVE-2026-26061 yet

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies without enforcing a size limit. An unauthenticated attacker could exploit this behavior by sending large or repeated HTTP payloads, causing excessive memory allocation and resulting in a denial-of-service (DoS) condition. Version 4.81.0 patches the issue.

Affected products
Envoy, Fleet, Nginx
Fleetdm Fleet
< 4.81.0
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
7.5 HIGH
EPSS
0.4% (36th percentile)
Weakness
CWE-770
NVD status
Analyzed
Published
2026-03-27
CVE-2026-26061 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-26061 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-26061 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.