CVE-2026-73500

EUVD-2026-57642
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 51.1%
Debian logo
Debian Releases
Debian Product
Codename
etcd
bookworm
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
etcd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cert-manager
Azure Linux 3.0
0:1.12.15-12.azl3
fixed
cloud-provider-kubevirt
Azure Linux 3.0
0:0.5.1-7.azl3
fixed
flannel
Azure Linux 3.0
0:0.24.2-30.azl3
fixed
keda
Azure Linux 3.0
0:2.14.1-17.azl3
fixed
kube-vip-cloud-provider
Azure Linux 3.0
0:0.0.10-8.azl3
fixed
kubernetes
Azure Linux 3.0
0:1.30.10-28.azl3
fixed
prometheus-adapter
Azure Linux 3.0
0:0.12.0-9.azl3
fixed