Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-59818
etcd: client certificate revocation list not enforced on the gRPC listener
Technology
etcd
CVSS Score
8.1 / 10.0
Affected Versions
etcd before 3.5.32, 3.6.0 to 3.6.12
Upstream Fix
3.5.32, 3.6.13; no fix for 3.4 and earlier
Published
July 8, 2026
OSSeva Coverage
Fixed upstream
Description
When --listen-client-http-urls splits the HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file revocation list is enforced only on the HTTP listener, so a client with a revoked certificate can still authenticate over gRPC. NVD's range covers every release below 3.5.32, including the end-of-life 3.4 line.
Is your etcd deployment affected?
If you're running etcd before 3.5.32, 3.6.0 to 3.6.12, you need this patch. Book a discovery call to get covered.