Impact
Elastic Fleet Server is vulnerable to an allocation of resources without limits or throttling flaw (CWE‑770). An attacker can send a specially crafted request to the server’s upload endpoint that causes the process to consume excessive memory, leading to memory exhaustion. The resulting denial of service can render the Fleet Server unavailable for legitimate users.
Affected Systems
The vulnerability affects Elastic’s Fleet Server product. The published data lists the vendor as Elastic and the product as Fleet Server, but no specific affected versions are documented, so users should assume all currently deployed instances could be vulnerable if they have not applied the latest patch.
Risk and Exploitability
The CVSS score of 6.5 classifies this vulnerability as moderate severity. The EPSS score of <1% indicates that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation activity. Based on the description, the likely attack vector is a remotely sent crafted request to the upload endpoint without requiring elevated privileges. Successful exploitation would consume unresponsive, resulting in service disruption.
OpenCVE Enrichment