GHSA-4r5r-ccr6-q6f6

Suggest an improvement
Source
https://github.com/advisories/GHSA-4r5r-ccr6-q6f6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-4r5r-ccr6-q6f6
Aliases
Published
2026-01-20T20:55:14Z
Modified
2026-03-19T08:48:11Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Fleet has an Access Control vulnerability in debug/pprof endpoints
Details

Summary

A broken access control issue in Fleet allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-privilege users could view internal server diagnostics and trigger resource-intensive profiling operations.

Impact

Fleet’s debug/pprof endpoints are accessible to any authenticated user regardless of role, including the lowest-privilege “Observer” role. This allows low-privilege users to access sensitive server internals, including runtime profiling data and in-memory application state, and to trigger CPU-intensive profiling operations that could lead to denial of service.

Patches

  • 4.78.3
  • 4.77.1
  • 4.76.2
  • 4.75.2
  • 4.53.3

Workarounds

If an immediate upgrade is not possible, users should put the debug/pprof endpoints behind an IP allowlist.

For more information

If you have any questions or comments about this advisory:

Email us at security@fleetdm.com Join #fleet in osquery Slack

Credits

We thank @secfox-ai for responsibly reporting this issue.

Database specific
{
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-20T20:55:14Z",
    "nvd_published_at": "2026-01-21T22:15:49Z",
    "severity": "HIGH"
}
References

Affected packages

Go
github.com/fleetdm/fleet

Package

Name
github.com/fleetdm/fleet
View open source insights on deps.dev
Purl
pkg:golang/github.com/fleetdm/fleet

Affected ranges

Type
SEMVER
Events
Introduced
4.78.0
Fixed
4.78.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json"
github.com/fleetdm/fleet

Package

Name
github.com/fleetdm/fleet
View open source insights on deps.dev
Purl
pkg:golang/github.com/fleetdm/fleet

Affected ranges

Type
SEMVER
Events
Introduced
4.77.0
Fixed
4.77.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json"
github.com/fleetdm/fleet

Package

Name
github.com/fleetdm/fleet
View open source insights on deps.dev
Purl
pkg:golang/github.com/fleetdm/fleet

Affected ranges

Type
SEMVER
Events
Introduced
4.76.0
Fixed
4.76.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json"
github.com/fleetdm/fleet

Package

Name
github.com/fleetdm/fleet
View open source insights on deps.dev
Purl
pkg:golang/github.com/fleetdm/fleet

Affected ranges

Type
SEMVER
Events
Introduced
4.75.0
Fixed
4.75.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json"
github.com/fleetdm/fleet/v4

Package

Name
github.com/fleetdm/fleet/v4
View open source insights on deps.dev
Purl
pkg:golang/github.com/fleetdm/fleet/v4

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.78.3-0.20260112221730-5c030e32a3a9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4r5r-ccr6-q6f6/GHSA-4r5r-ccr6-q6f6.json"