PatchSiren

etcd-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH etcd-io CVE published 2026-08-12

CVE-2026-73500

A vulnerability in etcd, a distributed key-value store, allows a network attacker to cause memory exhaustion by opening many TCP connections without sending a ClientHello, affecting availability of the cluster and control plane when etcd backs Kubernetes. This issue is fixed in etcd versions 3.5.33, 3.6.14, and 3.7.1. The vulnerability can be exploited by a network attacker who can reach an etcd TLS liste [truncated]

HIGH etcd-io CVE published 2026-08-12

CVE-2026-73499

A vulnerability in etcd, a distributed key-value store, allows users with READ permission on a single exact key to receive watch events for every key lexicographically greater than or equal to the permitted key using the Watch gRPC API with clientv3.WithFromKey(). This issue affects clusters with authentication enabled and is fixed in versions 3.5.33, 3.6.14, and 3.7.1.

MEDIUM etcd-io CVE published 2026-07-08

CVE-2026-59818

CVE-2026-59818 is a vulnerability in etcd, a distributed key-value store. Prior to versions 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener. This allows a client with a revoked certificate to authenticate successfully over gRPC. T [truncated]