CVE-2026-73500
etcd: TLS listener spawns unbounded handshake goroutines with no deadline
Technology
etcd
CVSS Score
8.7 / 10.0
Affected Versions
etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0
Upstream Fix
3.5.33, 3.6.14, 3.7.1; no fix for 3.4 and earlier
Published
August 12, 2026
OSSeva Coverage
Fixed upstream
Description
A network attacker who can reach an etcd TLS listener can open many connections and never send a ClientHello. Each one leaves a goroutine blocked in the TLS handshake and an entry in a tracking map, and their growth exhausts the server's memory, taking down the cluster and any Kubernetes control plane it backs. The affected range covers every release below 3.5.33, including the end-of-life 3.4 line. NVD has not analysed the record; the 8.7 score is the CVSS 4.0 score in the CNA record.
Is your etcd deployment affected?
If you're running etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0, you need this patch. Book a discovery call to get covered.