GO-2026-6107
Dashboard / Vulnerabilities / GO-2026-6107
Summary: Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Details: In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service.
References: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3, https://github.com/etcd-io/etcd/pull/22130, https://github.com/etcd-io/etcd/releases/tag/v3.5.33, https://github.com/etcd-io/etcd/releases/tag/v3.6.14, https://github.com/etcd-io/etcd/releases/tag/v3.7.1
Affected packages
Package
Name: go.etcd.io/etcd/client/pkg/v3
Purl: pkg:golang/go.etcd.io/etcd/client/pkg/v3
Affected ranges
Type: SEMVER
Events:
