Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher PublishLogs endpoint. In affected versions, certain unexpected input values were not handled gracefully, which could cause the Fleet server process to terminate while processing an authenticated request from an enrolled Launcher host.
An authenticated attacker with access to any enrolled Launcher node key could cause an immediate and complete denial of service by sending a single gRPC request to the PublishLogs endpoint.
This vulnerability impacts availability only. There is:
If upgrading immediately is not possible, the following mitigations can reduce exposure:
If you have any questions or concerns about this advisory, please contact us at:
Email us at security@fleetdm.com
We thank @fuzzztf for responsibly reporting this issue.
{
"github_reviewed_at": "2026-05-14T13:17:18Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-20"
],
"nvd_published_at": "2026-05-14T20:17:02Z",
"severity": "HIGH"
}