By vendor
Etcd vulnerabilities
Known CVEs affecting Etcd products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-59818MEDIUM 6.5
etcd, a widely-used distributed key-value store, has a certificate validation bypass when configured to split HTTP and gRPC traffic across separate listeners. In affected versions, the Certificate Revocation List (CRL) that should block revoked certificates is not applied to the gRPC listener, allowing an attacker with a revoked certificate to authenticate successfully. This affects etcd versions prior to 3.5.32 and 3.6.13, and is particularly relevant for organizations using etcd in Kubernetes clusters or other distributed systems where certificate-based access control is critical.