A AegiFlow
HIGHCVSS 8.7EPSS 0.4%

CVE-2026-73500

CVE-2026-73500 updated by NVD

Published
2026-07-24
Modified
2026-09-20
EPSS percentile
33%
Sources
github-advisory, nvd

Summary

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogo.etcd.io/etcd/v33.7.1, 3.6.14, 3.5.33

Remediation: Upgrade to 3.7.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.