go.etcd.io/etcd/client/pkg/v3
Activity
- Latest release
- 1mo ago
- Total releases
- 58
- Cadence
- ~17 days
- Last 12 months
- 24
Details
- First release
- May 18, 2021
| Version | Released | |
|---|---|---|
v3.7.1
patch
|
v3.7.1
patch
Dependencies (4)
|
|
v3.6.14
patch
|
v3.6.14
patch
Dependencies (4)
|
|
v3.5.33
patch
|
v3.5.33
patch
Dependencies (4)
|
|
v3.7.0
minor
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0
minor
Dependencies (4)
|
|
v3.6.13
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.13
patch
Dependencies (4)
|
|
v3.5.32
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.32
patch
Dependencies (4)
|
|
v3.8.0-alpha.0
pre
|
v3.8.0-alpha.0
pre
Dependencies (4)
|
|
v3.7.0-rc.0
pre
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-rc.0
pre
Dependencies (4)
|
|
v3.6.12
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.12
patch
Dependencies (4)
|
|
v3.5.31
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.31
patch
Dependencies (4)
|
|
v3.7.0-beta.0
pre
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-beta.0
pre
Dependencies (4)
|
|
v3.6.11
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.11
patch
Dependencies (4)
|
|
v3.5.30
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.30
patch
Dependencies (4)
|
|
v3.6.10
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.10
patch
Dependencies (4)
|
|
v3.5.29
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.29
patch
Dependencies (4)
|
|
v3.6.9
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.9
patch
Dependencies (4)
|
|
v3.5.28
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.28
patch
Dependencies (4)
|
|
v3.6.8
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.8
patch
Dependencies (4)
|
|
v3.5.27
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.27
patch
Dependencies (4)
|
|
v3.6.7
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.7
patch
Dependencies (4)
|
|
v3.5.26
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.26
patch
Dependencies (4)
|
|
v3.6.6
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.6
patch
Dependencies (4)
|
|
v3.5.25
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.25
patch
Dependencies (4)
|
|
v3.5.24
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.24
patch
Dependencies (4)
|
|
v3.6.5
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.5
patch
Dependencies (4)
|
|
v3.5.23
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.23
patch
Dependencies (4)
|
|
v3.6.4
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.4
patch
Dependencies (4)
|
|
v3.6.3
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.3
patch
Dependencies (4)
|
|
v3.5.22
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.22
patch
Dependencies (4)
|
|
v3.6.2
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.2
patch
Dependencies (4)
|
|
v3.6.1
minor
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.1
minor
Dependencies (4)
|
|
v3.7.0-alpha.0
pre
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-alpha.0
pre
Dependencies (4)
|
|
v3.6.0-rc.5
pre
|
v3.6.0-rc.5
pre
Dependencies (4)
|
|
v3.6.0-rc.4
pre
|
v3.6.0-rc.4
pre
Dependencies (4)
|
|
v3.5.21
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.21
patch
Dependencies (4)
|
|
v3.5.20
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.20
patch
Dependencies (4)
|
|
v3.5.19
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.19
patch
Dependencies (4)
|
|
v3.6.0-rc.2
pre
|
v3.6.0-rc.2
pre
Dependencies (4)
|
|
v3.6.0-rc.0
pre
|
v3.6.0-rc.0
pre
Dependencies (4)
|
|
v3.5.18
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.18
patch
Dependencies (4)
|
|
v3.5.17
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.17
patch
Dependencies (4)
|
|
v3.5.16
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.16
patch
Dependencies (4)
|
|
v3.5.15
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.15
patch
Dependencies (4)
|
|
v3.5.14
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.14
patch
Dependencies (4)
|
|
v3.5.13
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.13
patch
Dependencies (4)
|
|
v3.5.11
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.11
patch
Dependencies (4)
|
|
v3.5.10
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.10
patch
Dependencies (4)
|
|
v3.5.8
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.8
patch
Dependencies (4)
|
|
v3.5.7
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.7
patch
Dependencies (4)
|
|
v3.5.6
patch
1 CVE
CVE-2026-73500
GO-2026-6107
BIT-etcd-2026-73500
GHSA-6vch-q96h-7gc3
Aug 18, 2026
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service. Fixed in
3.5.33
3.6.14
3.7.1
References Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.6
patch
Dependencies (4)
|