- Sources: etcd advisory GHSA-xg4h-6gfc-h4m8, etcd advisory GHSA-6vch-q96h-7gc3, etcd 3.5.33 release
- Summary: etcd published two high-severity advisories on 2026-07-24 for releases tagged 2026-07-23. In the first, a user granted READ permission on one exact key can call the Watch gRPC API with an open-ended range (
clientv3.WithFromKey()) and receive watch events for every key lexicographically greater than or equal to the permitted key. The advisory calls this an authorization bypass in etcd's RBAC enforcement for Watch, states that Range, Get, and DeleteRange are unaffected, and notes it applies only to clusters with authentication enabled. The second advisory covers tlsListener.acceptLoop spawning unbounded handshake goroutines with no deadline. Both are fixed in 3.5.33, 3.6.14, and 3.7.1, with no CVE identifiers in the advisories. The affected version ranges are unknown here: this run did not resolve the advisories' own range fields, and the fixed versions above are the only version data read. The stated workarounds are auditing READ grants and restricting network access to the client gRPC port. Reporters are listed as Luis Toro, Anthropic, and Adam Korczynski. - Why it matters: etcd holds Kubernetes cluster state including Secrets, so an RBAC model that grants one key but leaks the rest of the keyspace over Watch turns a narrow credential into a full read of the control plane.
- Follow-up: Watch for CVE assignments, distribution and managed-Kubernetes backports of 3.5.33, 3.6.14, and 3.7.1, and any report of exploitation.
send feedback on this story