{"id":"GHSA-rxhg-vcww-2mpw","summary":"Fleet: ORDER BY column injection on activity list endpoints","details":"### Summary\n\nAn authenticated user with read access to Activity could influence the `ORDER BY` clause of the activity list endpoints by supplying an arbitrary sort column:\n\n- `GET /api/v1/fleet/activities` (`ListActivities`)\n- `GET /api/v1/fleet/hosts/{id}/activities` (`ListHostPastActivities`)\n\nThis originated from the deprecated cursor-pagination helper (`appendListOptionsWithCursorToSQL`), which interpolated the caller-supplied order key into SQL without an allowlist. The original report's `node_key` extraction scenario (`/api/v1/fleet/labels/{id}/hosts`) was remediated separately in #44385; these two activity endpoints were the residual call sites, neither of which joins the `hosts` table, so `node_key` was never reachable through them.\n\n### Impact\n\nRead-only. Because the order key was interpolated, an authenticated user with Activity read could sort by columns not otherwise returned in these responses. The exposure was bounded to columns on `activity_past` (e.g. `details` on `/api/v1/fleet/activities`, which is not in that endpoint's SELECT; host-only activities are already excluded by `WHERE host_only = false`). There is no privilege escalation, write access, or reachability of `node_key` or other host-join columns through these endpoints.\n\n### Remediation\n\nThe deprecated helper was removed from the codebase. Both endpoints now pass the caller-supplied sort column through `SanitizeColumn`, which strips all characters except `[\\w-.]` and backtick-quotes each identifier segment. This closes the injection vector: separators, whitespace, parentheses, and quotes cannot survive sanitization, so an expression-based `ORDER BY` oracle is not constructable.\n\n### Affected versions\n\n`\u003c fleet-v4.89.0`. Fixed in `fleet-v4.89.0`.\n\n### Credit\n\nThanks to @axel-corsiez for the report.","aliases":["CVE-2026-101046","GO-2026-6269"],"modified":"2026-09-28T03:55:39.119389082Z","published":"2026-08-20T18:44:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-20T18:44:36Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-rxhg-vcww-2mpw"},{"type":"PACKAGE","url":"https://github.com/fleetdm/fleet"},{"type":"WEB","url":"https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.0"}],"affected":[{"package":{"name":"github.com/fleetdm/fleet/v4","ecosystem":"Go","purl":"pkg:golang/github.com/fleetdm/fleet/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.89.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-rxhg-vcww-2mpw/GHSA-rxhg-vcww-2mpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}