<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:48:04 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-73500</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-73500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: etcd, Alpaquita:stream: etcd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: etcd, Alpaquita:stream: etcd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-73500</guid>
    </item>
    <item>
      <title>BIT-etcd-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
      <link>https://cve.radiocsirt.org/vuln/bit-etcd-2026-73500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: etcd&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: etcd&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-etcd-2026-73500</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AZ15466 — etcd is a distributed key-value store for the data of a distributed system</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-az15466</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cortex&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cortex package. etcd is a distributed key-value store for the data of a distributed system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cortex&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cortex package. etcd is a distributed key-value store for the data of a distributed system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-az15466</guid>
    </item>
    <item>
      <title>EUVD-2026-352268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352268</link>
      <description>EUVD-2026-352268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352268</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73500</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73500</link>
      <description>&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73500</guid>
    </item>
    <item>
      <title>GHSA-6vch-q96h-7gc3 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vch-q96h-7gc3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.etcd.io/etcd/v3&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and each is tracked in the pending map. Unbounded goroutine and map growth exhausts memory in the etcd process, causing loss of availability for the etcd cluster (and, when etcd backs Kubernetes, the control plane).&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;This vulnerability is patched in the following versions:&lt;/p&gt;
&lt;p&gt;- etcd 3.7.1
- etcd 3.6.14
- etcd 3.5.33&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;If upgrading is not immediately possible, then restrict network access. Limit which hosts can reach etcd&amp;#39;s client (gRPC) port via firewall rules or network policy, reducing who can attempt exploitation.&lt;/p&gt;
&lt;p&gt;### Reporter&lt;/p&gt;
&lt;p&gt;VMware By Broadcom&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.etcd.io/etcd/v3&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and each is tracked in the pending map. Unbounded goroutine and map growth exhausts memory in the etcd process, causing loss of availability for the etcd cluster (and, when etcd backs Kubernetes, the control plane).&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;This vulnerability is patched in the following versions:&lt;/p&gt;
&lt;p&gt;- etcd 3.7.1
- etcd 3.6.14
- etcd 3.5.33&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;If upgrading is not immediately possible, then restrict network access. Limit which hosts can reach etcd&amp;#39;s client (gRPC) port via firewall rules or network policy, reducing who can attempt exploitation.&lt;/p&gt;
&lt;p&gt;### Reporter&lt;/p&gt;
&lt;p&gt;VMware By Broadcom&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vch-q96h-7gc3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73500</link>
      <description>msrc_CVE-2026-73500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-73500</guid>
    </item>
    <item>
      <title>RHSA-2026:44868 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:44868</link>
      <description>&lt;p&gt;etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access etcd: etcd: Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener etcd: etcd: Denial of Service via unbounded TLS handshake goroutines&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access etcd: etcd: Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener etcd: etcd: Denial of Service via unbounded TLS handshake goroutines&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:44868</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73500</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: etcd, Ubuntu:Pro:18.04:LTS: etcd, Ubuntu:Pro:20.04:LTS: etcd, Ubuntu:Pro:22.04:LTS: etcd, Ubuntu:Pro:24.04:LTS: etcd, Ubuntu:Pro:26.04:LTS: etcd&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: etcd, Ubuntu:Pro:18.04:LTS: etcd, Ubuntu:Pro:20.04:LTS: etcd, Ubuntu:Pro:22.04:LTS: etcd, Ubuntu:Pro:24.04:LTS: etcd, Ubuntu:Pro:26.04:LTS: etcd&lt;/p&gt;
&lt;p&gt;etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73500</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2825 — etcd: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2825</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in etcd ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in etcd ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2825</guid>
    </item>
  </channel>
</rss>
