Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-73500

etcd: TLS listener spawns unbounded handshake goroutines with no deadline

Technology

etcd

CVSS Score

8.7 / 10.0

Affected Versions

etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0

Upstream Fix

3.5.33, 3.6.14, 3.7.1; no fix for 3.4 and earlier

Published

August 12, 2026

OSSeva Coverage

Fixed upstream

Description

A network attacker who can reach an etcd TLS listener can open many connections and never send a ClientHello. Each one leaves a goroutine blocked in the TLS handshake and an entry in a tracking map, and their growth exhausts the server's memory, taking down the cluster and any Kubernetes control plane it backs. The affected range covers every release below 3.5.33, including the end-of-life 3.4 line. NVD has not analysed the record; the 8.7 score is the CVSS 4.0 score in the CNA record.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.5.33, 3.6.0 to 3.6.13, 3.7.0, you need this patch. Book a discovery call to get covered.