GHSA-6vch-q96h-7gc3

    Dashboard / Vulnerabilities / GHSA-6vch-q96h-7gc3

    GHSA-6vch-q96h-7gc3

    Published: 24 Jul 2026Last Modified: 10 Sept 2026

    Summary: etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

    Details: ### Impact _What kind of vulnerability is it? Who is impacted?_ A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and each is tracked in the pending map. Unbounded goroutine and map growth exhausts memory in the etcd process, causing loss of availability for the etcd cluster (and, when etcd backs Kubernetes, the control plane). ### Patches _Has the problem been patched? What versions should users upgrade to?_ This vulnerability is patched in the following versions: - etcd 3.7.1 - etcd 3.6.14 - etcd 3.5.33 ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ If upgrading is not immediately possible, then restrict network access. Limit which hosts can reach etcd's client (gRPC) port via firewall rules or network policy, reducing who can attempt exploitation. ### Reporter VMware By Broadcom

    Affected packages

    Package

    Name: go.etcd.io/etcd/v3

    Purl: pkg:golang/go.etcd.io/etcd/v3

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.7.0-alpha.0
    Fixed -3.7.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High