CVE-2021-21296

Executive Summary

CVE-2021-21296: In Fleet versions prior to 3.7.0, an attacker possessing a valid node key can send a malformed request while a live query is active, causing the Fleet server to crash and resulting in a denial‑of‑service. The vulnerability does not lead to information disclosure, privilege escalation, or code execution. It was fixed in Fleet 3.7.0 and is not listed in the CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 2.7 (LOW) - Published: 2021-02-10T20:15:15.353 - Last Modified: 2026-10-06T14:18:40.287

Original Description: Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement that the actor has a valid node key. There is no information disclosure, privilege escalation, or code execution. The issue is fixed in Fleet 3.7.0.

"Great talent finds happiness in execution."

— Johann Wolfgang von Goethe
Source: NVD