go.etcd.io/etcd/server/v3
Activity
- Latest release
- 1mo ago
- Total releases
- 58
- Cadence
- ~17 days
- Last 12 months
- 24
Details
- First release
- May 18, 2021
| Version | Released | |
|---|---|---|
v3.7.1
patch
|
v3.7.1
patch
Dependencies (38)
+ 30 more |
|
v3.6.14
patch
|
v3.6.14
patch
Dependencies (40)
+ 32 more |
|
v3.5.33
patch
|
v3.5.33
patch
Dependencies (40)
+ 32 more |
|
v3.7.0
minor
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0
minor
Dependencies (38)
+ 30 more |
|
v3.6.13
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.13
patch
Dependencies (40)
+ 32 more |
|
v3.5.32
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.32
patch
Dependencies (40)
+ 32 more |
|
v3.8.0-alpha.0
pre
|
v3.8.0-alpha.0
pre
Dependencies (38)
+ 30 more |
|
v3.7.0-rc.0
pre
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-rc.0
pre
Dependencies (38)
+ 30 more |
|
v3.6.12
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.12
patch
Dependencies (40)
+ 32 more |
|
v3.5.31
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.31
patch
Dependencies (40)
+ 32 more |
|
v3.7.0-beta.0
pre
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-beta.0
pre
Dependencies (38)
+ 30 more |
|
v3.6.11
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.6.11
patch
Dependencies (40)
+ 32 more |
|
v3.5.30
patch
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.5.30
patch
Dependencies (40)
+ 32 more |
|
v3.6.10
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.10
patch
Dependencies (40)
+ 32 more |
|
v3.5.29
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.29
patch
Dependencies (40)
+ 32 more |
|
v3.6.9
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.9
patch
Dependencies (40)
+ 32 more |
|
v3.5.28
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.28
patch
Dependencies (40)
+ 32 more |
|
v3.6.8
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.8
patch
Dependencies (40)
+ 32 more |
|
v3.5.27
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.27
patch
Dependencies (40)
+ 32 more |
|
v3.6.7
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.7
patch
Dependencies (40)
+ 32 more |
|
v3.5.26
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.26
patch
Dependencies (40)
+ 32 more |
|
v3.6.6
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.6
patch
Dependencies (40)
+ 32 more |
|
v3.5.25
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.25
patch
Dependencies (40)
+ 32 more |
|
v3.5.24
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.24
patch
Dependencies (40)
+ 32 more |
|
v3.6.5
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.5
patch
Dependencies (40)
+ 32 more |
|
v3.5.23
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.23
patch
Dependencies (40)
+ 32 more |
|
v3.6.4
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.4
patch
Dependencies (40)
+ 32 more |
|
v3.6.3
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.3
patch
Dependencies (40)
+ 32 more |
|
v3.5.22
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.22
patch
Dependencies (40)
+ 32 more |
|
v3.6.2
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.2
patch
Dependencies (40)
+ 32 more |
|
v3.6.1
minor
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.6.1
minor
Dependencies (40)
+ 32 more |
|
v3.7.0-alpha.0
pre
1 CVE
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev |
v3.7.0-alpha.0
pre
Dependencies (40)
+ 32 more |
|
v3.6.0-rc.5
pre
|
v3.6.0-rc.5
pre
Dependencies (40)
+ 32 more |
|
v3.6.0-rc.4
pre
|
v3.6.0-rc.4
pre
Dependencies (40)
+ 32 more |
|
v3.5.21
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.21
patch
Dependencies (40)
+ 32 more |
|
v3.5.20
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.20
patch
Dependencies (40)
+ 32 more |
|
v3.5.19
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.19
patch
Dependencies (40)
+ 32 more |
|
v3.6.0-rc.2
pre
|
v3.6.0-rc.2
pre
Dependencies (40)
+ 32 more |
|
v3.6.0-rc.0
pre
|
v3.6.0-rc.0
pre
Dependencies (40)
+ 32 more |
|
v3.5.18
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.18
patch
Dependencies (40)
+ 32 more |
|
v3.5.17
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.17
patch
Dependencies (40)
+ 32 more |
|
v3.5.16
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.16
patch
Dependencies (40)
+ 32 more |
|
v3.5.15
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.15
patch
Dependencies (40)
+ 32 more |
|
v3.5.14
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.14
patch
Dependencies (40)
+ 32 more |
|
v3.5.13
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.13
patch
Dependencies (40)
+ 32 more |
|
v3.5.11
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.11
patch
Dependencies (39)
+ 31 more |
|
v3.5.10
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.10
patch
Dependencies (39)
+ 31 more |
|
v3.5.8
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.8
patch
Dependencies (39)
+ 31 more |
|
v3.5.7
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.7
patch
Dependencies (39)
+ 31 more |
|
v3.5.6
patch
2 CVEs
CVE-2026-73499
GO-2026-6114
BIT-etcd-2026-73499
GHSA-xg4h-6gfc-h4m8
Aug 18, 2026
Watch API authorization bypass in go.etcd.io/etcd/server/v3 In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticated user with READ permission on a single key can bypass RBAC restrictions by initiating an open-ended range watch using clientv3.WithFromKey(). The Watch RPC handler normalized open-ended range ends prior to authorization checks, causing isWatchPermitted to evaluate the request as a single-key watch while the underlying watch stream received events for all keys lexicographically greater than or equal to the target key. Fixed in
3.5.33
3.6.14
3.7.1
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-44283
GO-2026-5736
BIT-etcd-2026-44283
GHSA-x35m-3gp4-4fh5
Jul 24, 2026
Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v3 in go.etcd.io/etcd/server Fixed in
3.5.30
3.6.11
Updated Jul 25, 2026 · Source: OSV.dev |
v3.5.6
patch
Dependencies (39)
+ 31 more |