Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-59818

etcd: client certificate revocation list not enforced on the gRPC listener

Technology

etcd

CVSS Score

8.1 / 10.0

Affected Versions

etcd before 3.5.32, 3.6.0 to 3.6.12

Upstream Fix

3.5.32, 3.6.13; no fix for 3.4 and earlier

Published

July 8, 2026

OSSeva Coverage

Fixed upstream

Description

When --listen-client-http-urls splits the HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file revocation list is enforced only on the HTTP listener, so a client with a revoked certificate can still authenticate over gRPC. NVD's range covers every release below 3.5.32, including the end-of-life 3.4 line.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.5.32, 3.6.0 to 3.6.12, you need this patch. Book a discovery call to get covered.