etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1.
https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
https://github.com/etcd-io/etcd/releases/tag/v3.7.1
https://github.com/etcd-io/etcd/releases/tag/v3.6.14
https://github.com/etcd-io/etcd/releases/tag/v3.5.33
https://github.com/etcd-io/etcd/pull/22130
https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057
https://github.com/etcd-io/etcd/commit/8e4dd0679a2c6b095d2a32a749fda2521c7809a3
https://github.com/etcd-io/etcd/commit/89ff6d50796049d4f1136915ba21504b76e7e372
https://github.com/etcd-io/etcd/commit/2e07efce9745004eb4773cffaada9b5cdf77cff2
Published: 2026-08-12
Updated: 2026-08-12
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity: High
Base Score: 8.7
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity: High