<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:48:31.364230+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-73500</id>
    <title>BELL-CVE-2026-73500</title>
    <updated>2026-10-02T17:48:31.416514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: etcd, Alpaquita:stream: etcd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-73500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-etcd-2026-73500</id>
    <title>BIT-etcd-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
    <updated>2026-10-02T17:48:31.416607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: etcd</p>
<p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-etcd-2026-73500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az15466</id>
    <title>CLEANSTART-2026-AZ15466 — etcd is a distributed key-value store for the data of a distributed system</title>
    <updated>2026-10-02T17:48:31.416640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cortex</p>
<p>Security vulnerability affects the cortex package. etcd is a distributed key-value store for the data of a distributed system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az15466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352268</id>
    <title>EUVD-2026-352268</title>
    <updated>2026-10-02T17:48:31.416670+00:00</updated>
    <content>EUVD-2026-352268</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73500</id>
    <title>fkie_cve-2026-73500</title>
    <updated>2026-10-02T17:48:31.416684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6vch-q96h-7gc3</id>
    <title>GHSA-6vch-q96h-7gc3 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
    <updated>2026-10-02T17:48:31.416710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: go.etcd.io/etcd/v3</p>
<p>### Impact
_What kind of vulnerability is it? Who is impacted?_</p>
<p>A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and each is tracked in the pending map. Unbounded goroutine and map growth exhausts memory in the etcd process, causing loss of availability for the etcd cluster (and, when etcd backs Kubernetes, the control plane).</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>This vulnerability is patched in the following versions:</p>
<p>- etcd 3.7.1
- etcd 3.6.14
- etcd 3.5.33</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>If upgrading is not immediately possible, then restrict network access. Limit which hosts can reach etcd's client (gRPC) port via firewall rules or network policy, reducing who can attempt exploitation.</p>
<p>### Reporter</p>
<p>VMware By Broadcom</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6vch-q96h-7gc3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73500</id>
    <title>msrc_CVE-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
    <updated>2026-10-02T17:48:31.416749+00:00</updated>
    <content>msrc_CVE-2026-73500</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-73500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:44868</id>
    <title>RHSA-2026:44868 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T17:48:31.416825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access etcd: etcd: Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener etcd: etcd: Denial of Service via unbounded TLS handshake goroutines</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:44868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73500</id>
    <title>UBUNTU-CVE-2026-73500</title>
    <updated>2026-10-02T17:48:31.416861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: etcd, Ubuntu:Pro:18.04:LTS: etcd, Ubuntu:Pro:20.04:LTS: etcd, Ubuntu:Pro:22.04:LTS: etcd, Ubuntu:Pro:24.04:LTS: etcd, Ubuntu:Pro:26.04:LTS: etcd</p>
<p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2825</id>
    <title>WID-SEC-W-2026-2825 — etcd: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:48:31.416890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in etcd ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2825"/>
  </entry>
</feed>
