Launch Week Day 1: Announcing Security Design Review
go

go.etcd.io/etcd/v3

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Vulnerabilities

NONE 0.0
Go

CVE-2026-44283

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

UNKNOWN
Go

CVE-2026-33343

Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd

NONE 0.0
Go

CVE-2026-33343

etcd: Nested etcd transactions bypass RBAC authorization checks

UNKNOWN
Go

CVE-2026-33413

etcd: Authorization bypasses in multiple APIs

UNKNOWN
Go

CVE-2026-33413

Authorization bypasses in multiple APIs in go.etcd.io/etcd

MEDIUM 5.3
Go

CVE-2020-15106

etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic

UNKNOWN
Go

GO-2024-2528

Etcd Gateway TLS endpoint validation only confirms TCP reachability

UNKNOWN
Go

GHSA-pm3m-32r3-7mfh

Etcd embed auto compaction retention negative value causing a compaction loop or a crash in go.etcd.io/etcd

UNKNOWN
Go

GHSA-vjg6-93fv-qv64

Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only in go.etcd.io/etcd

UNKNOWN
Go

GHSA-j86v-2vjr-fg8f

Etcd Gateway TLS endpoint validation only confirms TCP reachability in go.etcd.io/etcd

HIGH 8.1
Go

CVE-2018-16886

go.etcd.io/etcd Authentication Bypass

UNKNOWN
Go

GO-2024-2529

Etcd embed auto compaction retention negative value causing a compaction loop or a crash

UNKNOWN
Go

GO-2024-2530

Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only

HIGH 7.5
Go

GHSA-65rp-cv85-263x

etcd denial of service vulnerability

CRITICAL 9.8
Go

CVE-2021-28235

Etcd-io Improper Authentication vulnerability

HIGH 8.8
Go

CVE-2018-1098

etcd Cross-site Request Forgery (CSRF)

UNKNOWN
Go

GHSA-h8g9-6gvh-5mrc

etcd vulnerable to TOCTOU of gateway endpoint authentication

Ready to move

Start Securing

Free, no credit card | First findings in minutes