etcd has 8 CVEs on record between 2022 and 2026. 4 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. Most affected products: go.etcd.io/etcd/v3 (4), etcd (1), go.etcd.io/etcd (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.2
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- go.etcd.io/etcd/v3 4
- etcd 1
- go.etcd.io/etcd 1
- go.etcd.io/etcd/client/pkg/v3 1
- go.etcd.io/etcd/client/v3 1
Worst active — by depth score
CVE-2020-15114High· 7.7Etcd Gateway can include itself as an endpoint resulting in resource exhaustion43CVE-2026-73499Highetcd is a distributed key-value store for the data of a distributed system41GHSA-xg4h-6gfc-h4m8Highetcd: Watch API authorization bypass via open-ended range requests41GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline41CVE-2026-59818Medium· 6.5etcd is a distributed key-value store for the data of a distributed system36
etcd vulnerabilities
CVEs affecting etcd, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-73499Highetcd is a distributed key-value store for the data of a distributed system
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to recei…
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-xg4h-6gfc-h4m8Highetcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
CVE-2026-59818Medium· 6.5etcd is a distributed key-value store for the data of a distributed system
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-…
GHSA-5x4g-q5rc-36jpLowEtcd pkg Insecure ciphers are allowed by default
Etcd pkg Insecure ciphers are allowed by default
CVE-2020-15114High· 7.7Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
CVE-2020-15115Medium· 5.8etcd has no minimum password length
etcd has no minimum password length
CVE-2020-15106Medium· 5.3etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic