VulnSea

etcd has 8 CVEs on record between 2022 and 2026. 4 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. Most affected products: go.etcd.io/etcd/v3 (4), etcd (1), go.etcd.io/etcd (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
4 prev 0

Products

  • go.etcd.io/etcd/v3 4
  • etcd 1
  • go.etcd.io/etcd 1
  • go.etcd.io/etcd/client/pkg/v3 1
  • go.etcd.io/etcd/client/v3 1
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

etcd vulnerabilities

CVEs affecting etcd, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-73499High
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to recei…

Twilightetcd · go.etcd.io/etcd/v3EPSS 0.36%via NVD
GHSA-6vch-q96h-7gc3High
2mo ago

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-xg4h-6gfc-h4m8High
2mo ago

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

Twilightetcd · go.etcd.io/etcd/v3via GHSA
CVE-2026-59818Medium· 6.5
2mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-…

Sunlitetcd · etcdEPSS 0.43%via NVD
GHSA-5x4g-q5rc-36jpLow
2y ago

Etcd pkg Insecure ciphers are allowed by default

Etcd pkg Insecure ciphers are allowed by default

Sunlitetcd · go.etcd.io/etcd/client/pkg/v3via OSV
CVE-2020-15114High· 7.7
2y ago

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

Twilightetcd · go.etcd.io/etcdEPSS 1.2%via OSV
CVE-2020-15115Medium· 5.8
3y ago

etcd has no minimum password length

etcd has no minimum password length

Sunlitetcd · go.etcd.io/etcd/client/v3EPSS 1.3%via OSV
CVE-2020-15106Medium· 5.3
3y ago

etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

Sunlitetcd · go.etcd.io/etcd/v3EPSS 1.3%via OSV
etcd vulnerabilities (CVEs) · VulnSea