CVE-2026-59818
EUVD-2026-4242608.07.2026, 21:16
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| etcd | etcd | 𝑥 < 3.5.32 |
| etcd | etcd | 3.6.0 ≤ 𝑥 < 3.6.13 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References