#1144346 etcd: CVE-2026-73499 CVE-2026-73500

Package:
src:etcd
Source:
src:etcd
Submitter:
Salvatore Bonaccorso
Date:
2026-08-14 07:05:02 UTC
Severity:
normal
Tags:
#1144346#5
Date:
2026-08-14 07:02:13 UTC
From:
To:
Hi,

The following vulnerabilities were published for etcd.

CVE-2026-73499[0]:
| etcd is a distributed key-value store for the data of a distributed
| system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted
| READ permission on a single exact key can use the Watch gRPC API
| with clientv3.WithFromKey() to receive watch events for every key
| lexicographically greater than or equal to the permitted key. In
| server/etcdserver/api/v3rpc/watch.go, the open-ended RangeEnd
| sentinel is rewritten before the RBAC permission check in
| server/auth/range_perm_cache.go function isRangeOpPermitted, causing
| the request to be treated as an exact-key watch. Range/Get and
| DeleteRange requests are not affected, and the issue affects only
| clusters with authentication enabled. This issue is fixed in
| versions 3.5.33, 3.6.14, and 3.7.1.


CVE-2026-73500[1]:
| etcd is a distributed key-value store for the data of a distributed
| system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network
| attacker who can reach an etcd TLS listener can open many TCP
| connections and never send a ClientHello. In
| client/pkg/transport/listener_tls.go, each connection handled by
| tlsListener.acceptLoop spawns a goroutine that blocks indefinitely
| inside tls.Conn.Handshake() and remains tracked in the pending map.
| Unbounded goroutine and map growth can exhaust memory in the etcd
| process, causing loss of availability for the cluster and, when etcd
| backs Kubernetes, the control plane. This issue is fixed in versions
| 3.5.33, 3.6.14, and 3.7.1.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-73499
https://www.cve.org/CVERecord?id=CVE-2026-73499
[1] https://security-tracker.debian.org/tracker/CVE-2026-73500
https://www.cve.org/CVERecord?id=CVE-2026-73500

Regards,
Salvatore