8.1

CVE-2026-59818

etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Etcd ≫ Etcd Version < 3.5.32
Etcd ≫ Etcd Version >= 3.6.0 < 3.6.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.239
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 6.5 1.2 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://github.com/etcd-io/etcd/security/advisories/GHSA-3wh4-j44w-pg92
Vendor Advisory
Mitigation
https://github.com/etcd-io/etcd/pull/22007
Patch
Issue Tracking
https://github.com/etcd-io/etcd/pull/22021
Patch
Issue Tracking
https://github.com/etcd-io/etcd/pull/22025
Patch
Issue Tracking
https://github.com/etcd-io/etcd/commit/2308ce1578064641d4d67c40f0487309267d1bef
Patch
https://github.com/etcd-io/etcd/commit/24838af5a53dd0245adced920e42a9bf0e7a267f
Patch
https://github.com/etcd-io/etcd/commit/8221ae82bc25d4d55ca64382207b69be71038cbb
Patch
https://github.com/etcd-io/etcd/releases/tag/v3.5.32
Product
Release Notes
https://github.com/etcd-io/etcd/releases/tag/v3.6.13
Product
Release Notes