go.etcd.io/etcd/v3 vulnerabilities
CVEs whose affected-version data names the go.etcd.io/etcd/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-73499Highetcd is a distributed key-value store for the data of a distributed system
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to recei…
▾ Twilightetcd · go.etcd.io/etcd/v3EPSS 0.36%via NVD
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-xg4h-6gfc-h4m8Highetcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
CVE-2020-15106Medium· 5.3etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
▾ Sunlitetcd · go.etcd.io/etcd/v3EPSS 1.3%via OSV