Hi, The following vulnerabilities were published for etcd. CVE-2026-73499[0]: | etcd is a distributed key-value store for the data of a distributed | system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted | READ permission on a single exact key can use the Watch gRPC API | with clientv3.WithFromKey() to receive watch events for every key | lexicographically greater than or equal to the permitted key. In | server/etcdserver/api/v3rpc/watch.go, the open-ended RangeEnd | sentinel is rewritten before the RBAC permission check in | server/auth/range_perm_cache.go function isRangeOpPermitted, causing | the request to be treated as an exact-key watch. Range/Get and | DeleteRange requests are not affected, and the issue affects only | clusters with authentication enabled. This issue is fixed in | versions 3.5.33, 3.6.14, and 3.7.1. CVE-2026-73500[1]: | etcd is a distributed key-value store for the data of a distributed | system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network | attacker who can reach an etcd TLS listener can open many TCP | connections and never send a ClientHello. In | client/pkg/transport/listener_tls.go, each connection handled by | tlsListener.acceptLoop spawns a goroutine that blocks indefinitely | inside tls.Conn.Handshake() and remains tracked in the pending map. | Unbounded goroutine and map growth can exhaust memory in the etcd | process, causing loss of availability for the cluster and, when etcd | backs Kubernetes, the control plane. This issue is fixed in versions | 3.5.33, 3.6.14, and 3.7.1. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73499 https://www.cve.org/CVERecord?id=CVE-2026-73499 [1] https://security-tracker.debian.org/tracker/CVE-2026-73500 https://www.cve.org/CVERecord?id=CVE-2026-73500 Regards, Salvatore