CVE-2026-73500
- EPSS 0.4%
- Veröffentlicht 12.08.2026 21:22:25
- Zuletzt bearbeitet 18.09.2026 20:05:53
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/t...
CVE-2026-59818
- EPSS 0.32%
- Veröffentlicht 08.07.2026 21:00:18
- Zuletzt bearbeitet 13.07.2026 14:50:12
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Cert...
CVE-2026-44283
- EPSS 0.23%
- Veröffentlicht 14.05.2026 17:01:33
- Zuletzt bearbeitet 15.05.2026 18:24:59
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC ...
CVE-2026-33413
- EPSS 0.25%
- Veröffentlicht 26.03.2026 13:36:10
- Zuletzt bearbeitet 26.03.2026 20:39:29
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call certain etcd functions in clusters that expose the ...
CVE-2026-33343
- EPSS 0.21%
- Veröffentlicht 26.03.2026 13:23:48
- Zuletzt bearbeitet 26.03.2026 20:41:35
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use nested transactions to bypass all key-level authoriz...
CVE-2022-34038
- EPSS 1.31%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 21.11.2024 07:08:49
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.
CVE-2023-32082
- EPSS 0.74%
- Veröffentlicht 11.05.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:40
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't ha...
CVE-2021-28235
- EPSS 1.61%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 09.07.2026 01:16:49
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVE-2020-15112
- EPSS 1.26%
- Veröffentlicht 05.08.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:04:50
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd con...
CVE-2020-15113
- EPSS 0.23%
- Veröffentlicht 05.08.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:04:50
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permi...