GHSA-xg4h-6gfc-h4m8High▾ Twilightetcd: Watch API authorization bypass via open-ended range requests
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
What kind of vulnerability is it? Who is impacted?
A user granted READ permission on a single, exact key can use the Watch gRPC API with clientv3.WithFromKey() (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexicographically greater than or equal to their permitted key — not just the one key they were granted.
This is an authorization bypass in etcd's RBAC enforcement for the Watch API; Range/Get and DeleteRange requests are not affected. It only affects clusters with authentication enabled — clusters running without auth already allow unrestricted read access.
Has the problem been patched? What versions should users upgrade to?
This vulnerability is patched in the following versions:
Is there a way for users to fix or remediate the vulnerability without upgrading?
If upgrading is not immediately possible, the following mitigations reduce exposure:
go.etcd.io/etcd/v3 >= 3.7.0-alpha.0, < 3.7.1go.etcd.io/etcd/v3 >= 3.6.0, < 3.6.14go.etcd.io/etcd/v3 < 3.5.33Upgrade to a patched release:
go.etcd.io/etcd/v3 3.7.1go.etcd.io/etcd/v3 3.6.14go.etcd.io/etcd/v3 3.5.33Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73499Highetcd is a distributed key-value store for the data of a distributed system
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
CVE-2020-15106Medium· 5.3etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
GHSA-5x4g-q5rc-36jpLowEtcd pkg Insecure ciphers are allowed by default
CVE-2020-15115Medium· 5.8etcd has no minimum password length
CVE-2020-15114High· 7.7Etcd Gateway can include itself as an endpoint resulting in resource exhaustion